An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, and django.views.i18n.set_language are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.
References
Configurations
No configuration.
History
02 Apr 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
02 Apr 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-02 13:15
Updated : 2025-04-02 22:15
NVD link : CVE-2025-27556
Mitre link : CVE-2025-27556
CVE.ORG link : CVE-2025-27556
JSON object : View
Products Affected
No product.
CWE
CWE-770
Allocation of Resources Without Limits or Throttling