CVE-2025-64458

An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is slow on Windows. As a consequence, `django.http.HttpResponseRedirect`, `django.http.HttpResponsePermanentRedirect`, and the shortcut `django.shortcuts.redirect` were subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:54

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en 5.1 anterior a 5.1.14, 4.2 anterior a 4.2.26 y 5.2 anterior a 5.2.8. La normalización NFKC en Python es lenta en Windows. Como consecuencia, 'django.http.HttpResponseRedirect', 'django.http.HttpResponsePermanentRedirect' y el atajo 'django.shortcuts.redirect' estuvieron sujetos a un potencial ataque de denegación de servicio a través de ciertas entradas con un número muy grande de caracteres Unicode. Series de Django anteriores y no compatibles (como 5.0.x, 4.1.x y 3.2.x) no fueron evaluadas y también pueden estar afectadas. Django desea agradecer a Seokchan Yoon por informar este problema.

10 Nov 2025, 18:33

Type Values Removed Values Added
CPE cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
First Time Djangoproject django
Djangoproject
References () https://docs.djangoproject.com/en/dev/releases/security/ - () https://docs.djangoproject.com/en/dev/releases/security/ - Vendor Advisory
References () https://groups.google.com/g/django-announce - () https://groups.google.com/g/django-announce - Mailing List
References () https://www.djangoproject.com/weblog/2025/nov/05/security-releases/ - () https://www.djangoproject.com/weblog/2025/nov/05/security-releases/ - Vendor Advisory

05 Nov 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

05 Nov 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-05 15:15

Updated : 2026-06-17 09:54


NVD link : CVE-2025-64458

Mitre link : CVE-2025-64458

CVE.ORG link : CVE-2025-64458


JSON object : View

Products Affected

djangoproject

  • django
CWE
CWE-407

Inefficient Algorithmic Complexity