HIGH 7.5 PyPI

Django vulnerable to Denial of Service

GHSA-qg2p-9jwr-mmqf · BIT-django-2024-38875 · CVE-2024-38875 · PYSEC-2024-56

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack via certain inputs with a very large number of brackets.

Ready to move

Start Securing

Free, no credit card | First findings in minutes