CVE-2023-43665: Djangoproject Django
High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.
In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain inputs with very long, potentially malformed HTML text. The chars() and words() methods are used to implement the truncatechars_html and truncatewords_html template filters, which are thus also vulnerable. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232.
Affected products
- Djangoproject Django: from 3.2, before 3.2.22 (fixed in 3.2.22); from 4.1, before 4.1.12 (fixed in 4.1.12); from 4.2, before 4.2.6 (fixed in 4.2.6)
- Fedoraproject Fedora: version 39 only
Published 2023-11-03. Last modified 2026-06-17.