CVE-2024-56374: Debian Linux
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)
Affected products
- Debian Debian Linux: version 11.0 only
- Djangoproject Django: from 4.2, before 4.2.18 (fixed in 4.2.18); from 5.0, before 5.0.11 (fixed in 5.0.11); from 5.1, before 5.1.5 (fixed in 5.1.5)
Published 2025-01-14. Last modified 2026-06-17.