CVE-2025-64460: Potential denial-of-service vulnerability in XML serializer text extraction
An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. Algorithmic complexity in django.core.serializers.xmlserializer.getInnerText() allows a remote attacker to cause a potential denial-of-service attack triggering CPU and memory exhaustion via specially crafted XML input processed by the XML Deserializer. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64460?
CVE-2025-64460 is classified as a potential denial-of-service vulnerability due to algorithmic complexity.
How do I fix CVE-2025-64460?
To mitigate CVE-2025-64460, upgrade Django to versions 5.2.9, 5.1.15, or 4.2.27 or later.
What versions of Django are affected by CVE-2025-64460?
Django versions prior to 5.2.9, 5.1.15, and 4.2.27 are affected by CVE-2025-64460.
What type of attack can CVE-2025-64460 facilitate?
CVE-2025-64460 can facilitate a denial-of-service attack due to CPU and memory exhaustion.
Is there a workaround for CVE-2025-64460?
There are no documented workarounds for CVE-2025-64460; upgrading to a fixed version is recommended.