First published: Fri Jul 05 2024(Updated: )
get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings including a specific set of characters. Affected versions ================= * Django main development branch * Django 5.1 * Django 5.0 * Django 4.2
Affected Software | Affected Version | How to fix |
---|---|---|
Django | >main development branch |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2295938 is categorized as a potential denial-of-service vulnerability affecting certain versions of Django.
To fix REDHAT-BUG-2295938, you should update to a patched version of Django that addresses this vulnerability.
Affected versions include Django 5.1, Django 5.0, Django 4.2, and the main development branch.
The main risk is a possible denial-of-service attack resulting from the handling of very long strings in a specific format.
Yes, if your application uses an affected version of Django, it may be vulnerable to the issues described in REDHAT-BUG-2295938.