CVE-2026-105315
Received Received - Intake

Improper Neutralization in django-haystack more_like_this Tag Handler

Vulnerability report for CVE-2026-105315, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: VulDB

Description

A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file haystack/backends/elasticsearch_backend.py of the component more_like_this Template Tag Handler. Such manipulation of the argument result_class leads to improper neutralization of directives in dynamically evaluated code. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.4.0 is able to address this issue. The name of the patch is eb05f193c9771a68dcc8cfac6674a0d48a52ee9d. It is suggested to upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
n/a django-haystack 3.0
n/a django-haystack 3.1
n/a django-haystack 3.2
n/a django-haystack 3.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CWE-95 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Remote Code Execution (RCE) flaw in the django-haystack library affecting the Elasticsearch backend. It occurs when a SearchField uses an index_fieldname alias different from the logical field name. During result processing, the backend fails to find the field under the alias key, causing the value to fall through to _to_python(), which then calls eval() on raw Elasticsearch field values. An attacker who controls indexed content and triggers a search can execute arbitrary Python code, including shell commands, in the Django application process with the web server's privileges.

Detection Guidance

To detect this vulnerability, check if your django-haystack version is below 3.4.0. Run: pip show django-haystack. If installed, verify the Elasticsearch backend usage in your Django project settings. Inspect the file haystack/backends/elasticsearch_backend.py for the presence of eval() calls in the _to_python function.

Impact Analysis

An attacker could exploit this to execute arbitrary code on your server, potentially stealing data, installing malware, or disrupting services. Since the attack can be launched remotely and requires no authentication, any Django application using the Elasticsearch backend with index_fieldname aliasing is at risk. The impact includes full system compromise with the privileges of the web server process.

Compliance Impact

This vulnerability could lead to unauthorized data access, modification, or exfiltration, violating GDPR's data protection principles and HIPAA's security requirements. Non-compliance may result in legal penalties, fines, or reputational damage. Organizations must address this flaw to maintain regulatory compliance and protect sensitive data.

Mitigation Strategies

Immediately upgrade django-haystack to version 3.4.0 or later using: pip install --upgrade django-haystack. If using Elasticsearch backend, ensure no index_fieldname aliasing is misconfigured. Review and remove any eval() usage in custom backend code.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105315. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart