CVE-2026-3902 | Django up to 4.2.29/5.2.12/6.0.3 ASGIRequest authentication spoofing
A vulnerability, which was classified as critical, was found in Django up to 4.2.29/5.2.12/6.0.3. This affects an unknown function of the component ASGIRequest. The manipulation results in authentication bypass by spoofing.
This vulnerability is known as CVE-2026-3902. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.