VDB
PYSEC-2025-13
PYSEC-2025-13
PUBLISHED
CVSS 8.699999809265137 HIGH
An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.
Risk Scores
CVSS v4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PyPI | django | 5.1, 5.0, 4.2 |
Timeline
- Mar 6, 2025 CVE Published
- Apr 9, 2025 CVE Updated
References
- https://lists.debian.org/debian-lts-announce/2025/03/msg00012.html advisory
- https://www.djangoproject.com/weblog/2025/mar/06/security-releases/ article
- https://docs.djangoproject.com/en/dev/releases/security/ url
- https://groups.google.com/g/django-announce url
- http://www.openwall.com/lists/oss-security/2025/03/06/12 url