CVE-2019-14233: Djangoproject Django
High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behaviour of the underlying HTMLParser, django.utils.html.strip_tags would be extremely slow to evaluate certain inputs containing large sequences of nested incomplete HTML entities.
Affected products
- Djangoproject Django: from 1.11, before 1.11.23 (fixed in 1.11.23); from 2.1, before 2.1.11 (fixed in 2.1.11); from 2.2, before 2.2.4 (fixed in 2.2.4)
- Opensuse Leap: version 15.1 only
Published 2019-08-02. Last modified 2026-06-17.