First published: Fri Feb 28 2025(Updated: )
The ``wrap()`` and :tfilter:`wordwrap` template filter were subject to a potential denial-of-service attack when used with very long strings. Affected versions ================= * Django main development branch * Django 5.2 (currently at beta status) * Django 5.1 * Django 5.0 * Django 4.2
Affected Software | Affected Version | How to fix |
---|---|---|
Django | >=4.2<5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2348993 has been identified as a potential denial-of-service vulnerability.
To mitigate REDHAT-BUG-2348993, update Django to the latest patched version.
REDHAT-BUG-2348993 affects Django versions from 4.2 up to, but not including, 5.2.
The issue in REDHAT-BUG-2348993 pertains to the potential for denial-of-service attacks with the wrap() and wordwrap template filters.
No, REDHAT-BUG-2348993 is specifically related to certain versions of Django, particularly from 4.2 to 5.2.