Skip to content

[Snyk - Medium] Allocation of Resources vulnerability in Django 5.2.11 (due 5/10/26) #1923

@exalate-issue-sync

Description

@exalate-issue-sync

Detailed paths and remediation

…and 6 more

Security information

Factors contributing to the scoring:

  • Snyk: CVSS v4.0 6.3 - Medium Severity | CVSS v3.1 3.7 - Low Severity
  • NVD: Not available. NVD has not yet published its analysis.

Why are the scores different? Learn how Snyk evaluates vulnerability scores

Overview

Django is a high-level Python Web framework that encourages rapid development and clean, pragmatic design.

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in the URLField.to_python() function when processing URLs containing certain Unicode characters on Windows systems. An attacker can cause excessive resource consumption and application unresponsiveness by submitting large URL inputs crafted with these characters.

QA Notes

null

DEV Notes

null

Design

null

See full ticket and images here: FECFILE-2938

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions