It's certainly possible. Maybe, maybe not.
The recent spate of Rails vulnerabilities - the really scary ones at least - all stemmed from the same root cause: folks were a little too lenient with how they handled YAML parsing.
Once that was discovered, a lot more attention has been directed to how Rails handles different kinds of parsing.
It's possible! that other frameworks have had similar cascading mistakes, but we won't know until more code reviews occur. Maybe in this particular case Rails-core was especially lenient, but (as far as I remember) dedicated security people have only taken a keener interest in the past year or so.
With regard to this vulnerability, however, the '^' and '$' regex pattern characters in python match the beginning and end (or end + '\n') of the string by default. Multiline mode has to be enabled explicitly:
import re
re.match(r'^test$', 'test\n multiline') == None
re.match(r'^test$', 'test\n multiline', re.MULTILINE) != None
So, I think it's a little less likely that this particular vulnerability would be an issue. It's still possible for someone to leave off the '$', but at least that case is a little more obvious.
Also, the Django codebase doesn't have any param processing code that uses whitelisting/blacklisting like this; you have to explicitly lookup values in request.GET and request.POST or use specific field names in a Form. It's a little less convenient compared to mass assignment, but more secure by default.
class SomeForm(ModelForm):
class Meta:
model = SomeModel
fields = [ whitelist ]
exclude = [ blacklist ]
Both fields and exclude are optional, if neither are specified 'all'[2] fields for the model will be included in the form.[1] https://docs.djangoproject.com/en/1.4/topics/forms/modelform...
[2] The model can blacklist certain fields with editable=False in the field definition as well, which afaik trumps anything a ModelForm does.
That is not to say Django doesn't have issues; it undoubtably does. I just think the hidden surface area is smaller.
If you are using PyYaml.Loader instead of PyYaml.SafeLoader for anything coming from a user, you are at risk of this problem.
http://pyyaml.org/wiki/PyYAMLDocumentation#YAMLtagsandPython...
I cannot remember the last time I came across a php project that did something similar.
Beyond that, your guess is as good as mine. I'm sure that /someone/ has been looking at Django at least to see if there are similar issues.
(we tend to keep an eye out for issues affecting other frameworks/libraries, both to coordinate and to check our own stuff -- security is really damned hard, and the thing to do is watch and learn rather than point and laugh)