UBUNTU-CVE-2026-3902

Source
https://ubuntu.com/security/CVE-2026-3902
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-3902.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-3902
Upstream
  • CVE-2026-3902
Downstream
Published
2026-04-07T14:00:00Z
Modified
2026-04-08T15:12:48.385694Z
Severity
  • Ubuntu - low
Summary
[none]
Details

ASGI header spoofing via underscore/hyphen conflation

References

Affected packages

Ubuntu:22.04:LTS / python-django

Package

Name
python-django
Purl
pkg:deb/ubuntu/python-django@2:3.2.12-2ubuntu1.26?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:2.*
2:2.2.24-1ubuntu1
2:3.*
2:3.2.12-2
2:3.2.12-2ubuntu1
2:3.2.12-2ubuntu1.1
2:3.2.12-2ubuntu1.2
2:3.2.12-2ubuntu1.3
2:3.2.12-2ubuntu1.4
2:3.2.12-2ubuntu1.5
2:3.2.12-2ubuntu1.6
2:3.2.12-2ubuntu1.7
2:3.2.12-2ubuntu1.8
2:3.2.12-2ubuntu1.9
2:3.2.12-2ubuntu1.10
2:3.2.12-2ubuntu1.11
2:3.2.12-2ubuntu1.12
2:3.2.12-2ubuntu1.13
2:3.2.12-2ubuntu1.14
2:3.2.12-2ubuntu1.15
2:3.2.12-2ubuntu1.16
2:3.2.12-2ubuntu1.17
2:3.2.12-2ubuntu1.18
2:3.2.12-2ubuntu1.19
2:3.2.12-2ubuntu1.20
2:3.2.12-2ubuntu1.21
2:3.2.12-2ubuntu1.22
2:3.2.12-2ubuntu1.23
2:3.2.12-2ubuntu1.24
2:3.2.12-2ubuntu1.25
2:3.2.12-2ubuntu1.26

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-django",
            "binary_version": "2:3.2.12-2ubuntu1.26"
        }
    ],
    "priority_reason": "Django developers have rated this as being a low severity issue"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-3902.json"

Ubuntu:24.04:LTS / python-django

Package

Name
python-django
Purl
pkg:deb/ubuntu/python-django@3:4.2.11-1ubuntu1.15?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3:4.*
3:4.2.4-1ubuntu2
3:4.2.8-1
3:4.2.9-1
3:4.2.11-1
3:4.2.11-1ubuntu1
3:4.2.11-1ubuntu1.1
3:4.2.11-1ubuntu1.2
3:4.2.11-1ubuntu1.3
3:4.2.11-1ubuntu1.4
3:4.2.11-1ubuntu1.5
3:4.2.11-1ubuntu1.6
3:4.2.11-1ubuntu1.7
3:4.2.11-1ubuntu1.8
3:4.2.11-1ubuntu1.9
3:4.2.11-1ubuntu1.10
3:4.2.11-1ubuntu1.11
3:4.2.11-1ubuntu1.12
3:4.2.11-1ubuntu1.13
3:4.2.11-1ubuntu1.14
3:4.2.11-1ubuntu1.15

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-django",
            "binary_version": "3:4.2.11-1ubuntu1.15"
        }
    ],
    "priority_reason": "Django developers have rated this as being a low severity issue"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-3902.json"

Ubuntu:25.10 / python-django

Package

Name
python-django
Purl
pkg:deb/ubuntu/python-django@3:5.2.4-1ubuntu2.4?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3:4.*
3:4.2.18-1ubuntu1
3:4.2.18-1ubuntu1.1
3:5.*
3:5.2.4-1
3:5.2.4-1ubuntu1
3:5.2.4-1ubuntu2
3:5.2.4-1ubuntu2.1
3:5.2.4-1ubuntu2.2
3:5.2.4-1ubuntu2.3
3:5.2.4-1ubuntu2.4

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-django",
            "binary_version": "3:5.2.4-1ubuntu2.4"
        }
    ],
    "priority_reason": "Django developers have rated this as being a low severity issue"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-3902.json"