CVE-2024-45230: Djangoproject Django

High severity, CVSS 7.5. EPSS: 25.8% chance of exploitation in the next 30 days.

An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.

Affected products

  • Djangoproject Django: from 4.2.0, before 4.2.16 (fixed in 4.2.16); from 5.0, before 5.0.9 (fixed in 5.0.9); version 5.1 only

Published 2024-10-08. Last modified 2026-06-17.