An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.
                
            References
                    | Link | Resource | 
|---|---|
| https://docs.djangoproject.com/en/dev/releases/security/ | Patch Vendor Advisory | 
| https://groups.google.com/forum/#%21forum/django-announce | Not Applicable | 
| https://www.djangoproject.com/weblog/2024/aug/06/security-releases/ | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    07 Aug 2024, 20:48
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://docs.djangoproject.com/en/dev/releases/security/ - Patch, Vendor Advisory | |
| References | () https://groups.google.com/forum/#%21forum/django-announce - Not Applicable | |
| References | () https://www.djangoproject.com/weblog/2024/aug/06/security-releases/ - Vendor Advisory | |
| CWE | CWE-1284 | |
| First Time | 
        
        Djangoproject
         Djangoproject django  | 
|
| CPE | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | 
07 Aug 2024, 18:35
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 7.5  | 
| CWE | CWE-130 | 
07 Aug 2024, 15:17
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-08-07 15:15
Updated : 2024-08-07 20:48
NVD link : CVE-2024-41991
Mitre link : CVE-2024-41991
CVE.ORG link : CVE-2024-41991
JSON object : View
Products Affected
                djangoproject
- django
 
