Elias Myllymäki discovered that Django incorrectly handled stripping large sequences of incomplete HTML tags. A remote attacker could possibly use this issue to cause Django to consume resources, leading to a denial of service.
{ "binaries": [ { "binary_name": "python3-django", "binary_version": "2:2.2.12-1ubuntu0.29" } ], "availability": "No subscription required" }
{ "cves": [], "ecosystem": "Ubuntu:20.04:LTS" }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7501-1.json"
{ "binaries": [ { "binary_name": "python3-django", "binary_version": "2:3.2.12-2ubuntu1.18" } ], "availability": "No subscription required" }
{ "cves": [], "ecosystem": "Ubuntu:22.04:LTS" }
{ "binaries": [ { "binary_name": "python3-django", "binary_version": "3:4.2.11-1ubuntu1.7" } ], "availability": "No subscription required" }
{ "cves": [], "ecosystem": "Ubuntu:24.04:LTS" }