Denial-of-Service Vulnerability in Django by Django Software Foundation
CVE-2024-41991
7.5HIGH
What is CVE-2024-41991?
A vulnerability affecting Django versions 5.0 prior to 5.0.8 and 4.2 prior to 4.2.15 allows for potential denial-of-service attacks. The issue arises from the urlize and urlizetrunc template filters, along with the AdminURLFieldWidget widget, which can be manipulated through specific inputs containing a significantly large quantity of Unicode characters. This vulnerability poses risks to applications utilizing these components, making it essential for users to promptly update to the latest secure versions.
