Django Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2015-2317
The utils.http.is_safe_url function in Django before 1.4.20 1.5.x 1.6.x before 1.6.11 1.7.x before 1.7.7 and 1.8.x before 1.8c1 does not properly validate URLs which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL as demonstrated by a x08javascript: URL.