CVE-2016-2513: Djangoproject Django

Low severity, CVSS 3.1. EPSS: 3.3% chance of exploitation in the next 30 days.

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.

Affected products

  • Djangoproject Django: version 1.8.9 only; version 1.9 only; version 1.9.1 only; version 1.9.2 only

Published 2016-04-08. Last modified 2026-06-17.