Django Denial-of-Service Vulnerability in Text Wrapping Functions

Vulnerability

A denial-of-service vulnerability has been identified in Django versions 5.1 prior to 5.1.7, 5.0 prior to 5.0.13, and 4.2 prior to 4.2.20. The issue arises in the 'django.utils.text.wrap()' method and the wordwrap template filter, which can be exploited with very long strings, potentially leading to a denial-of-service condition.

Impact

Exploitation of this vulnerability can lead to a denial-of-service condition, causing the application to become unresponsive or slow down significantly.

Remediation

Users can upgrade to Django versions 5.1.7, 5.0.13, or 4.2.20 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.6
impact
2.5
exploitability
5.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.