CVE-2023-46695: Django: CVE-2023-46695: Potential denial of service vulnerability in UsernameField on Windows
An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.forms.UsernameField is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Django vulnerability?
The vulnerability ID for this Django vulnerability is CVE-2023-46695.
What is the title of this Django vulnerability?
The title of this Django vulnerability is 'Potential denial of service vulnerability in UsernameField on Windows'.
What is the severity level of this Django vulnerability?
The severity level of this Django vulnerability is not mentioned in the provided information. Please refer to the provided references for more details.
How can I fix this Django vulnerability?
To fix this Django vulnerability, update Django to version 3.2.23, 4.1.13, or 4.2.7 depending on your current version.
Where can I find more information about this Django vulnerability?
You can find more information about this Django vulnerability in the provided references.