{"id":"PYSEC-2026-328","summary":"django-s3file is vulnerable to relative path traversal","details":"### Impact\n`S3FileMiddleware` is vulnerable to relative path traversal attacks, where an attacker can use a modified request to escape pre-signed upload locations and have the Django application load files from random locations into `request.FILES`\n\nDepending on how files are handled, this may lead to confidentiality and integrity issues.\n\n### Patches\nDjango-S3File urges all users to update to a patched version \u003e=7.0.2.","aliases":["CVE-2026-42196","GHSA-67qg-7284-2277"],"modified":"2026-07-13T16:15:23.624771324Z","published":"2026-06-29T11:50:49.713473Z","references":[{"type":"WEB","url":"https://github.com/codingjoe/django-s3file/security/advisories/GHSA-67qg-7284-2277"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42196"},{"type":"PACKAGE","url":"https://github.com/codingjoe/django-s3file"},{"type":"PACKAGE","url":"https://pypi.org/project/django-s3file"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-67qg-7284-2277"}],"affected":[{"package":{"name":"django-s3file","ecosystem":"PyPI","purl":"pkg:pypi/django-s3file"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.2"}]}],"versions":["0.1.0","0.1.1","0.1.10","0.1.11","0.1.12","0.1.13","0.1.14","0.1.15","0.1.16","0.1.17","0.1.18","0.1.19","0.1.2","0.1.20","0.1.21","0.1.22","0.1.23","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9","0.2.0","0.3.0","0.3.1","0.3.2","0.3.3","0.3.4","0.3.5","0.3.6","0.3.7","0.4.0","0.4.1","0.5.0","0.5.1","0.5.2","0.5.3","0.5.4","0.6.0","0.6.1","0.6.2","1.0.0","1.0.1","1.0.2","1.1.0","1.2.0","1.2.1","2.0.0","3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","4.0.0","4.0.1","4.0.2","4.1.0","4.2.0","5.0.0","5.0.1","5.0.2","5.0.4","5.0.5","5.0.6","5.1.0","5.1.1","5.1.2","5.1.3","5.2.0","5.3.0","5.4.0","5.5.0","5.5.1","5.5.2","5.5.3","5.5.4","5.5.5","5.5.7","6.0.1","7.0.0","7.0.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/django-s3file/PYSEC-2026-328.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"}]}