Django: backtracking in a regular expression in django.utils.text.Truncator leads to DoS
Published Aug 2, 2019
8.7
HIGHCVSS 4.0
EPSS 3.53%
Description
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs due to a catastrophic backtracking vulnerability in a regular expression. The chars() and words() methods are used to implement the truncatechars_html and truncatewords_html template filters, which were thus vulnerable.
Affected products
No data.
Configuration 1
- ≥ 1.11 · < 1.11.23
- ≥ 2.1 · < 2.1.11
- ≥ 2.2 · < 2.2.4
-
- Version 1.11.23StatusaffectedConstraints<2.2.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Djangoblog Project | Djangoblog | n/a |
|
Red Hat OpenStack Platform 13.0 (Queens)
python-django-0:1.11.27-1.el7ost
Fixed · RHSA-2020:4390
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS
python-django-0:1.11.27-1.el7ost
Fixed · RHSA-2020:4390
Red Hat OpenStack Platform 15.0 (Stein)
python-django-0:2.1.11-1.el8ost
Fixed · RHSA-2020:1324
Red Hat Ceph Storage 2
calamari-server
Not affected
Red Hat Ceph Storage 2
python-django
Will not fix
Red Hat Ceph Storage 3
python-django
Will not fix
Red Hat Certification for Red Hat Enterprise Linux 7
python-django
Fix deferred
Red Hat OpenStack Platform 10 (Newton)
python-django
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
python-django
Out of support scope
Red Hat OpenStack Platform 9 (Mitaka)
python-django
Will not fix
Red Hat OpenStack Platform 9 (Mitaka) Operational Tools
python-django
Will not fix
Red Hat Satellite 6
python-django
Not affected
Red Hat Storage 3
python-django
Fix deferred
Red Hat Update Infrastructure 3 for Cloud Providers
python-django
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 13.0 (Queens) | python-django-0:1.11.27-1.el7ost | Fixed | RHSA-2020:4390 |
| Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS | python-django-0:1.11.27-1.el7ost | Fixed | RHSA-2020:4390 |
| Red Hat OpenStack Platform 15.0 (Stein) | python-django-0:2.1.11-1.el8ost | Fixed | RHSA-2020:1324 |
| Red Hat Ceph Storage 2 | calamari-server | Not affected | n/a |
| Red Hat Ceph Storage 2 | python-django | Will not fix | n/a |
| Red Hat Ceph Storage 3 | python-django | Will not fix | n/a |
| Red Hat Certification for Red Hat Enterprise Linux 7 | python-django | Fix deferred | n/a |
| Red Hat OpenStack Platform 10 (Newton) | python-django | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | python-django | Out of support scope | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | python-django | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | python-django | Will not fix | n/a |
| Red Hat Satellite 6 | python-django | Not affected | n/a |
| Red Hat Storage 3 | python-django | Fix deferred | n/a |
| Red Hat Update Infrastructure 3 for Cloud Providers | python-django | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of python-django as shipped with Red Hat Gluster Storage 3, Red Hat Ceph Storage 2 and 3, as it contains the vulnerable code. This issue affects Red Hat Update Infrastructure for Cloud Providers, but the vulnerable functions in python-django are currently not used in any part of the Product. This issue does not affect Red Hat Satellite as the vulnerable functions in python-django are not used. Red Hat OpenStack Platform: * This issue affects all versions of python-django shipped with Red Hat Openstack Platform versions 9-15, as it contains the vulnerable code. * Because the flaw's impact is Medium, it will not be fixed in Red Hat Openstack Platform 9 which is retiring on 8/24.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed May 2, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (23 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 3.53% (0.03531) | 88.88th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.53% (0.03531) | 87.72th | v5 (v2026.06.15) |
| Aug 24, 2025 | 3.63% (0.03634) | 87.37th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.29% (0.02289) | 83.55th | v4 (v2025.03.14) |
| Dec 17, 2024 | 1.49% (0.01486) | 86.52th | v3 (v2023.03.01) |
| Jul 26, 2024 | 4.24% (0.04243) | 92.36th | v3 (v2023.03.01) |
| May 2, 2024 | 2.87% (0.02866) | 90.62th | v3 (v2023.03.01) |
| Nov 26, 2023 | 2.84% (0.02838) | 89.61th | v3 (v2023.03.01) |
| Nov 8, 2023 | 2.05% (0.02048) | 87.71th | v3 (v2023.03.01) |
| Oct 5, 2023 | 1.79% (0.01788) | 86.66th | v3 (v2023.03.01) |
| Jul 9, 2023 | 1.48% (0.01484) | 85.01th | v3 (v2023.03.01) |
| Jun 23, 2023 | 1.30% (0.01302) | 83.96th | v3 (v2023.03.01) |
| Jun 6, 2023 | 0.96% (0.00959) | 81.06th | v3 (v2023.03.01) |
| May 22, 2023 | 0.70% (0.00698) | 77.39th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.58% (0.00585) | 74.83th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.54% (0.01537) | 74.52th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.54% (0.01537) | 74.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.54% (0.01537) | 72.41th | v2 (v2022.01.01) |
| Feb 4, 2022 | 16.31% (0.16306) | 92.84th | v2 (v2022.01.01) |
| Feb 3, 2022 | 9.45% (0.09448) | 86.95th | v1 |
| Jan 6, 2022 | 9.45% (0.09448) | 86.79th | v1 |
| Sep 1, 2021 | 2.27% (0.02273) | 77.89th | v1 |
| Apr 14, 2021 | 2.27% (0.02273) | 0.00th | v1 |
References (24)
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html vendor-advisoryThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html vendor-advisory
- http://www.openwall.com/lists/oss-security/2023/10/04/6 mailing-list
- http://www.openwall.com/lists/oss-security/2024/03/04/1 mailing-list
- https://access.redhat.com/security/cve/CVE-2019-14232 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1734405 Issue Tracking
- https://docs.djangoproject.com/en/dev/releases/security PatchVendor Advisory
- https://github.com/advisories/GHSA-c4qh-4vgv-qc6g Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2019-11.yaml
- https://github.com/pypa/advisory-db/tree/main/vulns/django/PYSEC-2019-11.yaml
- https://groups.google.com/forum/#!topic/django-announce/jIoju2-KLDs
- https://groups.google.com/forum/#%21topic/django-announce/jIoju2-KLDs
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/STVX7X7IDWAH5SKE6MBMY3TEI6ZODBTK vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/STVX7X7IDWAH5SKE6MBMY3TEI6ZODBTK
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/3LGJSPCN3VEG2UJPYCUB6TU75JTIV2TQ
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/5XTP44JEOSNXRVW4JDZXA5XGMBDZLWSW
- https://nvd.nist.gov/vuln/detail/CVE-2019-14232
- https://seclists.org/bugtraq/2019/Aug/15 mailing-list
- https://security.gentoo.org/glsa/202004-17 vendor-advisory
- https://security.netapp.com/advisory/ntap-20190828-0002
- https://www.cve.org/CVERecord?id=CVE-2019-14232
- https://www.debian.org/security/2019/dsa-4498 vendor-advisory
- https://www.djangoproject.com/weblog/2019/aug/01/security-releases Vendor Advisory
- https://www.openwall.com/lists/oss-security/2023/10/04/6
Change history (0)
No recorded changes yet.