A reflected cross-site scripting risk was highlighted in Django applications that include request.method in HttpResponseBadRequest output. Because HTTP/1.1 allows custom request methods, an attacker can supply an arbitrary verb that Django normalizes to uppercase, turning the HTTP method into an unexpected user-controlled input source that may be reflected into HTML error responses.
The report showed that, despite constraints such as forced uppercase and the inability to use spaces, crafted payloads can still produce exploitable markup, including malicious anchor tags. Browser-based exploitation is more limited because XMLHttpRequest and the Fetch API restrict unusual characters in HTTP verbs, but the pattern remains unsafe; defenders were advised to avoid reflecting request.method in responses and to use Semgrep rules to detect this Django anti-pattern.

See affected versions and whether adversaries are exploiting it.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.