CVE-2026-42196CWE-22CWE-26

django-s3file: Relative path traversal

Critical · published May 12, 2026

CVSS v4.0
9.9
EPSS
1%
Percentile
44.8
In the wild
Unconfirmed
What it is

django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerable to relative path traversal attacks, where an attacker can use a modified request to escape pre-signed upload locations and have the Django application load files from random locations into request.FILES. Depending on how files are handled, this may lead to confidentiality and integrity issues. This vulnerability is fixed in 7.0.2.

The record
Technical detail
CVSS v4.0
9.9 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
EPSS
0.00565 · 44.8th percentile
Weaknesses
CWE-22 · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'); CWE-26 · Path Traversal: '/dir/../filename'
Published
2026-05-12T20:58Z
EPSS history
Timeline
  • 12 MAY 20:58Z
    django-s3file: Relative path traversal
    cvelistv5