Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 PyPI

Django Denial of service vulnerability in django.utils.encoding.uri_to_iri

GHSA-7h4p-27mh-hmrw · BIT-django-2023-41164 · CVE-2023-41164 · PYSEC-2023-225

Published · Modified

Description

In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.

Ready to move

Start Securing

Free, no credit card | First findings in minutes