Django denial-of-service vulnerability in internationalized URLs
High severity
GitHub Reviewed
Published
Oct 16, 2022
to the GitHub Advisory Database
•
Updated Sep 20, 2024
Package
Affected versions
>= 3.2, < 3.2.16
>= 4.0, < 4.0.8
>= 4.1, < 4.1.2
Patched versions
3.2.16
4.0.8
4.1.2
Description
Published by the National Vulnerability Database
Oct 16, 2022
Published to the GitHub Advisory Database
Oct 16, 2022
Reviewed
Oct 18, 2022
Last updated
Sep 20, 2024
In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.
References