MEDIUM 5.3 PyPI

Django Denial of service vulnerability in django.utils.encoding.uri_to_iri

GHSA-7h4p-27mh-hmrw · BIT-django-2023-41164 · CVE-2023-41164 · PYSEC-2023-225

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.

Ready to move

Start Securing

Free, no credit card | First findings in minutes