Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-25673

Опубликовано: 03 мар. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. URLField.to_python() in Django calls urllib.parse.urlsplit(), which performs NFKC normalization on Windows that is disproportionately slow for certain Unicode characters, allowing a remote attacker to cause denial of service via large URL inputs containing these characters. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.

РелизСтатусПримечание
devel

not-affected

windows-specific
esm-infra-legacy/trusty

not-affected

windows-specific
esm-infra-legacy/xenial

not-affected

windows-specific
esm-infra/bionic

not-affected

windows-specific
esm-infra/focal

not-affected

windows-specific
esm-infra/xenial

not-affected

windows-specific
jammy

not-affected

windows-specific
noble

not-affected

windows-specific
questing

not-affected

windows-specific
upstream

needs-triage

Показывать по

Ссылки на источники

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
5 месяцев назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normalization on Windows that is disproportionately slow for certain Unicode characters, allowing a remote attacker to cause denial of service via large URL inputs containing these characters. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.

CVSS3: 7.5
nvd
5 месяцев назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normalization on Windows that is disproportionately slow for certain Unicode characters, allowing a remote attacker to cause denial of service via large URL inputs containing these characters. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.

CVSS3: 7.5
debian
5 месяцев назад

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4. ...

CVSS3: 7.5
github
5 месяцев назад

Django vulnerable to Uncontrolled Resource Consumption

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость функции URLField.to_python() программной платформы для веб-приложений Django, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3