CVE-2019-6975: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 5.1% chance of exploitation in the next 30 days.
Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 18.10 only
- Djangoproject Django: from 1.11.0, before 1.11.19 (fixed in 1.11.19); from 2.0.0, before 2.0.11 (fixed in 2.0.11); from 2.1.0, before 2.1.6 (fixed in 2.1.6)
- Fedoraproject Fedora: version 28 only; version 29 only
Published 2019-02-11. Last modified 2026-06-17.