—
PYSEC-2026-1626
Mezzanine allows attackers to bypass access controls via manipulating the Host header
Details
An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/mezzanine
Introduced in:
0No fixed version published yet for mezzanine (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-25170[ADVISORY]
- https://github.com/shenhav12/CVE-2024-25170-Mezzanine-v6.0.0[WEB]
- https://github.com/stephenmcd/mezzanine[PACKAGE]
- https://ibb.co/DpxHpz9[WEB]
- https://ibb.co/T0fhLwR[WEB]
- https://pypi.org/project/mezzanine[PACKAGE]
- https://github.com/advisories/GHSA-22cc-w7xm-rfhx[ADVISORY]