CVE-2019-3498: Canonical Ubuntu Linux

Medium severity, CVSS 6.5. EPSS: 3.4% chance of exploitation in the next 30 days.

In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Djangoproject Django: from 1.11, before 1.11.18 (fixed in 1.11.18); from 2.0, before 2.0.10 (fixed in 2.0.10); from 2.1, before 2.1.5 (fixed in 2.1.5)
  • Fedoraproject Fedora: version 28 only

Published 2019-01-09. Last modified 2026-06-17.