CVE-2023-36053: Debian Linux
High severity, CVSS 7.5. EPSS: 3% chance of exploitation in the next 30 days.
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
Affected products
- Debian Debian Linux: version 10.0 only; version 11.0 only; version 12.0 only
- Djangoproject Django: from 3.2, before 3.2.20 (fixed in 3.2.20); from 4.0, before 4.1.10 (fixed in 4.1.10); from 4.2, before 4.2.3 (fixed in 4.2.3)
- Fedoraproject Fedora: version 37 only; version 38 only
Published 2023-07-03. Last modified 2026-06-17.