Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vrcr-9hj9-jcg6

Опубликовано: 02 дек. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.3

Описание

Django is vulnerable to DoS via XML serializer text extraction

An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. Algorithmic complexity in django.core.serializers.xml_serializer.getInnerText() allows a remote attacker to cause a potential denial-of-service attack triggering CPU and memory exhaustion via specially crafted XML input processed by the XML Deserializer. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 5.2a1, < 5.2.9

5.2.9

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 5.1a1, < 5.1.15

5.1.15

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 4.2a1, < 4.2.27

4.2.27

EPSS

Процентиль: 15%
0.00049
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-407

Связанные уязвимости

CVSS3: 7.5
ubuntu
16 дней назад

An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. Algorithmic complexity in `django.core.serializers.xml_serializer.getInnerText()` allows a remote attacker to cause a potential denial-of-service attack triggering CPU and memory exhaustion via specially crafted XML input processed by the XML `Deserializer`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.

CVSS3: 7.5
nvd
16 дней назад

An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. Algorithmic complexity in `django.core.serializers.xml_serializer.getInnerText()` allows a remote attacker to cause a potential denial-of-service attack triggering CPU and memory exhaustion via specially crafted XML input processed by the XML `Deserializer`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.

CVSS3: 7.5
debian
16 дней назад

An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4. ...

suse-cvrf
6 дней назад

Security update for python-Django

suse-cvrf
9 дней назад

Security update for python-Django

EPSS

Процентиль: 15%
0.00049
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-407