Djangoproject

Django

128 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.22%
  • Veröffentlicht 06.03.2025 19:15:27
  • Zuletzt bearbeitet 03.10.2025 00:32:38

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

  • EPSS 0.61%
  • Veröffentlicht 14.01.2025 19:15:32
  • Zuletzt bearbeitet 03.10.2025 13:16:13

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented...

  • EPSS 0.67%
  • Veröffentlicht 06.12.2024 12:15:18
  • Zuletzt bearbeitet 09.06.2025 19:51:17

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an...

  • EPSS 0.6%
  • Veröffentlicht 06.12.2024 12:15:17
  • Zuletzt bearbeitet 24.06.2025 14:55:06

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of n...

  • EPSS 2.72%
  • Veröffentlicht 08.10.2024 16:15:11
  • Zuletzt bearbeitet 17.03.2025 15:15:41

An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of charact...

  • EPSS 0.17%
  • Veröffentlicht 08.10.2024 16:15:11
  • Zuletzt bearbeitet 17.03.2025 18:15:17

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending passwor...

  • EPSS 0.56%
  • Veröffentlicht 07.08.2024 15:15:56
  • Zuletzt bearbeitet 04.11.2025 17:16:03

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given a string representation of a number in scientific notation with a large exponent.

  • EPSS 0.54%
  • Veröffentlicht 07.08.2024 15:15:56
  • Zuletzt bearbeitet 04.11.2025 17:16:03

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.

  • EPSS 0.37%
  • Veröffentlicht 07.08.2024 15:15:56
  • Zuletzt bearbeitet 04.11.2025 17:16:03

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service attack via certain inputs with a very large number...

  • EPSS 0.17%
  • Veröffentlicht 07.08.2024 15:15:56
  • Zuletzt bearbeitet 04.11.2025 17:16:04

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg.