CVE-2026-7666
Estado: AnalizadaBaja (2.3)—
An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake when `fail_silently=True`, which allows on-path network attackers to read email content via cleartext interception. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Kasper Dupont for reporting this issue.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 2.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-319
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-7666",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-7666",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-03T15:43:26.714914Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.1,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 1.6
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 2.3,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "PASSIVE",
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92",
"affectedData": [
{
"repo": "https://github.com/django/django/",
"vendor": "djangoproject",
"product": "Django",
"versions": [
{
"status": "affected",
"version": "6.0",
"lessThan": "6.0.6",
"versionType": "python"
},
{
"status": "unaffected",
"version": "6.0.6",
"versionType": "python"
},
{
"status": "affected",
"version": "5.2",
"lessThan": "5.2.15",
"versionType": "python"
},
{
"status": "unaffected",
"version": "5.2.15",
"versionType": "python"
}
],
"packageName": "django",
"collectionURL": "https://pypi.org/project/Django/",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-06-03T14:16:47.087",
"references": [
{
"url": "https://docs.djangoproject.com/en/dev/releases/security/",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"
},
{
"url": "https://groups.google.com/g/django-announce",
"tags": [
"Release Notes"
],
"source": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"
},
{
"url": "https://www.djangoproject.com/weblog/2026/jun/03/security-releases/",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15.\n`django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake when `fail_silently=True`, which allows on-path network attackers to read email content via cleartext interception.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Kasper Dupont for reporting this issue."
},
{
"lang": "es",
"value": "Se descubrió un problema en Django 6.0 anterior a 6.0.6 y 5.2 anterior a 5.2.15.\n'django.core.mail.backends.smtp.EmailBackend' en Django falla al evitar la reutilización de una conexión parcialmente inicializada después de un handshake 'STARTTLS' fallido cuando 'fail_silently=True', lo que permite a atacantes de red en la ruta leer el contenido del correo electrónico mediante intercepción de texto claro.\nSeries de Django anteriores no soportadas (como 5.0.x, 4.1.x y 3.2.x) no fueron evaluadas y también podrían estar afectadas.\nDjango desea agradecer a Kasper Dupont por reportar este problema."
}
],
"lastModified": "2026-07-21T19:10:00.107",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "048C450F-F81F-4A1D-9BF7-DC36FF26988E",
"versionEndExcluding": "5.2.15",
"versionStartIncluding": "5.2"
},
{
"criteria": "cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC9BA685-D9CE-406E-A479-9C444E8EADB3",
"versionEndExcluding": "6.0.6",
"versionStartIncluding": "6.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"
}