CVE-2024-45230: Djangoproject Django
High severity, CVSS 7.5. EPSS: 25.8% chance of exploitation in the next 30 days.
An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.
Affected products
- Djangoproject Django: from 4.2.0, before 4.2.16 (fixed in 4.2.16); from 5.0, before 5.0.9 (fixed in 5.0.9); version 5.1 only
Published 2024-10-08. Last modified 2026-06-17.