Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-25673

Опубликовано: 03 мар. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. URLField.to_python() in Django calls urllib.parse.urlsplit(), which performs NFKC normalization on Windows that is disproportionately slow for certain Unicode characters, allowing a remote attacker to cause denial of service via large URL inputs containing these characters. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.

A flaw was found in Django. A remote attacker can exploit a vulnerability in the URLField.to_python() function, specifically when Django is running on the Windows platform. This function, which utilizes urllib.parse.urlsplit(), performs a disproportionately slow normalization process for certain Unicode characters. By submitting large URL inputs containing these characters, an attacker can trigger a denial of service (DoS).

Отчет

This flaw only affects Django running on the Windows platform. As such, Red Hat software is unaffected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/eda-controller-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/gateway-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/hub-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform/automation-dashboard-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-tech-preview/automation-dashboard-rhel9Not affected
Red Hat Ansible Automation Platform 2automation-controllerNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2444115django: Django: Denial of Service via slow URL normalization on Windows

EPSS

Процентиль: 43%
0.00211
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
22 дня назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normalization on Windows that is disproportionately slow for certain Unicode characters, allowing a remote attacker to cause denial of service via large URL inputs containing these characters. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.

CVSS3: 7.5
nvd
22 дня назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normalization on Windows that is disproportionately slow for certain Unicode characters, allowing a remote attacker to cause denial of service via large URL inputs containing these characters. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.

CVSS3: 7.5
debian
22 дня назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4. ...

CVSS3: 7.5
github
22 дня назад

Django vulnerable to Uncontrolled Resource Consumption

EPSS

Процентиль: 43%
0.00211
Низкий

7.5 High

CVSS3