CVE-2024-53907: Djangoproject Django

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities.

Affected products

  • Djangoproject Django: from 4.2, before 4.2.17 (fixed in 4.2.17); from 5.0, before 5.0.10 (fixed in 5.0.10); from 5.1, before 5.1.4 (fixed in 5.1.4)

Published 2024-12-06. Last modified 2026-06-17.