CVE-2026-7666 Details
Description
An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake when `fail_silently=True`, which allows on-path network attackers to read email content via cleartext interception. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Kasper Dupont for reporting this issue.
A vulnerability exists in Django's SMTP email backend that could lead to unencrypted email transmission. This issue is present in Django versions 6.0 prior to 6.0.6 and 5.2 prior to 5.2.15. The vulnerability arises when 'fail_silently=True' is set, allowing on-path attackers to intercept email content in cleartext. This occurs because the backend fails to properly manage a partially-initialized connection after a failed STARTTLS handshake, reusing it for sending emails without encryption.
Users can upgrade to Django versions 6.0.6 or 5.2.15, both of which include the necessary patch. Instructions for downloading these versions are available on the Django website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.djangoproject.com/en/dev/releases/security/ | Django Software Foundation | PatchVendor Advisory |
| https://groups.google.com/g/django-announce | Django Software Foundation | Release Notes |
| https://www.djangoproject.com/weblog/2026/jun/03/security-releases/ | Django Software Foundation | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | Django Software Foundation |
Affected Products
| Product | Versions |
|---|---|
| djangoproject django | >= 5.2, < 5.2.15 >= 6.0, < 6.0.6 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | Django Software Foundation |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | Initial Analysis | [email protected] |
| Jun 3, 2026 | New CVE Received | Django Software Foundation |