Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-26699

Опубликовано: 06 мар. 2025
Источник: redhat
CVSS3: 7.5

Описание

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

A potential denial of service vulnerability exists in django.utils.text.wrap() and the wordwrap template filter. When processing extremely long strings, these functions may cause excessive resource consumption, potentially leading to service disruption.

Отчет

This vulnerability is rated as a Moderate severity because it exposes the wrap() method and wordwrap template filter to a potential denial of service attack. Malicious input containing extremely long strings could cause excessive processing, leading to resource exhaustion. However, it does not affect data confidentiality or integrity.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 1.2ansible-towerNot affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-dellemc-openmanage-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/platform-resource-runner-rhel8Not affected
Red Hat Satellite 6python-djangoFix deferred
Discovery 1 for RHEL 9discovery/discovery-server-rhel9FixedRHSA-2025:370908.04.2025
Red Hat Ansible Automation Platform 2.4 for RHEL 8python3x-djangoFixedRHSA-2025:860905.06.2025
Red Hat Ansible Automation Platform 2.4 for RHEL 9python-djangoFixedRHSA-2025:860905.06.2025
Red Hat Ansible Automation Platform 2.5 for RHEL 8python3.11-djangoFixedRHSA-2025:316025.03.2025
Red Hat Ansible Automation Platform 2.5 for RHEL 8ansible-automation-platform-25/lightspeed-rhel8FixedRHSA-2025:316225.03.2025
Red Hat Ansible Automation Platform 2.5 for RHEL 8automation-controllerFixedRHSA-2025:455306.05.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2348993django: Potential denial-of-service vulnerability in django.utils.text.wrap()

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 5
nvd
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 5
debian
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, ...

suse-cvrf
5 месяцев назад

Security update for python-Django

CVSS3: 5
github
5 месяцев назад

Django vulnerable to Allocation of Resources Without Limits or Throttling

7.5 High

CVSS3