Django
cpe:2.3:a:django_project:django:*:*:*:*:*:*:*
- < 5.2.9
- < 5.1.15
- < 4.2.27
A denial-of-service vulnerability has been identified in Django versions 5.2 prior to 5.2.9, 5.1 prior to 5.1.15, and 4.2 prior to 4.2.27. The issue arises from algorithmic complexity in the XML serializer's text extraction method, which can be exploited by remote attackers using specially crafted XML. This manipulated input causes CPU and memory exhaustion, leading to service degradation or outage.
Exploitation of this vulnerability can cause significant CPU and memory exhaustion, potentially leading to a service outage.
Users can upgrade to Django versions 5.2.9, 5.1.15, or 4.2.27 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.