CVE-2019-14235: Djangoproject Django
High severity, CVSS 7.5. EPSS: 3.1% chance of exploitation in the next 30 days.
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding.uri_to_iri could lead to significant memory usage due to a recursion when repercent-encoding invalid UTF-8 octet sequences.
Affected products
- Djangoproject Django: from 1.11, before 1.11.23 (fixed in 1.11.23); from 2.1, before 2.1.11 (fixed in 2.1.11); from 2.2, before 2.2.4 (fixed in 2.2.4)
- Opensuse Leap: version 15.1 only
Published 2019-08-02. Last modified 2026-06-17.