CVE-2024-24680
- EPSS 1%
- Published 06.02.2024 22:16:15
- Last modified 15.05.2025 20:15:47
An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.
CVE-2023-43665
- EPSS 1.45%
- Published 03.11.2023 05:15:30
- Last modified 21.11.2024 08:24:34
In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain inputs with very long, ...
CVE-2023-41164
- EPSS 0.43%
- Published 03.11.2023 05:15:29
- Last modified 21.11.2024 08:20:42
In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.
CVE-2023-46695
- EPSS 2.67%
- Published 02.11.2023 06:15:08
- Last modified 21.11.2024 08:29:05
An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.forms.UsernameField is subject to a potential DoS (denial of service) attac...
CVE-2023-36053
- EPSS 4.8%
- Published 03.07.2023 13:15:09
- Last modified 21.11.2024 08:09:14
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
CVE-2023-31047
- EPSS 0.06%
- Published 07.05.2023 02:15:08
- Last modified 29.01.2025 16:15:42
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only t...
CVE-2023-24580
- EPSS 14.7%
- Published 15.02.2023 01:15:10
- Last modified 18.03.2025 20:15:18
An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory...
CVE-2023-23969
- EPSS 1.01%
- Published 01.02.2023 19:15:08
- Last modified 27.03.2025 15:15:45
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the ra...
CVE-2022-41323
- EPSS 6.17%
- Published 16.10.2022 06:15:09
- Last modified 14.05.2025 15:15:49
In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.
CVE-2022-36359
- EPSS 0.59%
- Published 03.08.2022 14:15:08
- Last modified 21.11.2024 07:12:51
An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filena...