#1150169 django-haystack: CVE-2026-105315

Package:
src:django-haystack
Source:
src:django-haystack
Submitter:
Salvatore Bonaccorso
Date:
2026-10-06 12:03:04 UTC
Severity:
normal
Tags:
#1150169#5
Date:
2026-10-06 12:02:22 UTC
From:
To:
Hi,

The following vulnerability was published for django-haystack.

CVE-2026-105315[0]:
| A vulnerability has been found in django-haystack up to 3.3.0.
| Affected is the function _to_python of the file
| haystack/backends/elasticsearch_backend.py of the component
| more_like_this Template Tag Handler. Such manipulation of the
| argument result_class leads to improper neutralization of directives
| in dynamically evaluated code. The attack can be launched remotely.
| The exploit has been disclosed to the public and may be used.
| Upgrading to version 3.4.0 is able to address this issue. The name
| of the patch is eb05f193c9771a68dcc8cfac6674a0d48a52ee9d. It is
| suggested to upgrade the affected component.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-105315
https://www.cve.org/CVERecord?id=CVE-2026-105315
[1] https://github.com/django-haystack/django-haystack/security/advisories/GHSA-r3hx-x5rh-p9vv
[2] https://github.com/django-haystack/django-haystack/commit/eb05f193c9771a68dcc8cfac6674a0d48a52ee9d

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore