CVE-2024-41989: Djangoproject Django

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given a string representation of a number in scientific notation with a large exponent.

Affected products

  • Djangoproject Django: from 4.2, before 4.2.15 (fixed in 4.2.15); from 5.0, before 5.0.8 (fixed in 5.0.8)

Published 2024-08-07. Last modified 2026-06-17.