Django Anymail Project maintains a focused email-abstraction library for the Django web framework, allowing developers to switch among multiple mail service providers through a unified interface. The library's narrow exposure footprint reflects its specialized function in the application layer, and current severity, exploitation, and coverage metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Django Anymail Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6596CRITICAL webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post a | Feb 3, 2018 | 9.1 | 28 | NO | NO |
CVE-2018-1000089HIGH Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access t | Mar 13, 2018 | 7.4 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Django Anymail Project.
Media articles that mention a CVE ID that affects a product developed by Django Anymail Project — matched by CVE ID, not by vendor name.