Back

MEDIUM

python-django: Potential denial-of-service vulnerability in django.utils.html.urlize()

Published Aug 7, 2024

Description

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.

Affected products

Remediation

Red Hat mitigation

Implementing input validation and limiting the the size of inputs to the urlize and urlizetrunc will mitigate this vulnerability.

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 7, 2024
Updated Nov 4, 2025
Reserved Jul 25, 2024
CISA Vulnrichment
Updated Aug 7, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 6, 2024
ENISA EUVD
Assigner mitre
Published Aug 7, 2024
Updated Nov 4, 2025
Exploited since n/a
EUVD-2024-0045 GHSA-795C-9XPC-XW6G