VDB
CVE-2023-36053
CVE-2023-36053
PUBLISHED
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
EPSS 8.92% · 92.7th percentile
Risk Scores
EPSS Score
8.92%
92.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | django | 4.2.0, 4.2.0, 3.2.0 |
| Bitnami | django | 3.2.0, 4.2.0, 4.0.0 |
Timeline
- Jul 2, 2023 CVE Published
- Jul 4, 2023 EPSS Score
- Mar 21, 2025 EPSS Score
- Mar 22, 2025 EPSS Score
- Mar 25, 2025 EPSS Score
- Mar 28, 2025 EPSS Score
- Mar 29, 2025 EPSS Score
- Apr 5, 2025 EPSS Score
- Apr 11, 2025 EPSS Score
- Apr 15, 2025 EPSS Score
- May 1, 2025 EPSS Score
- Jun 1, 2025 EPSS Score
References
- https://docs.djangoproject.com/en/4.2/releases/security/ url
- https://groups.google.com/forum/#%21forum/django-announce url
- https://lists.debian.org/debian-lts-announce/2023/07/msg00022.html url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NRDGTUN4LTI6HG4TWR3JYLSFVXPZT42A/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XG5DYKPNDCEHJQ3TKPJQO7QGSR4FAYMS/ url
- https://www.debian.org/security/2023/dsa-5465 url
- https://www.djangoproject.com/weblog/2023/jul/03/security-releases/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQJOMNRMVPCN5WMIZ7YSX5LQ7IR2NY4D/ url
- https://nvd.nist.gov/vuln/detail/CVE-2023-36053 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZQJOMNRMVPCN5WMIZ7YSX5LQ7IR2NY4D/ url