CVE-2023-36053
03.07.2023, 13:15
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.Enginsight
Vendor | Product | Version |
---|---|---|
djangoproject | django | 3.2 ≤ 𝑥 < 3.2.20 |
djangoproject | django | 4.0 ≤ 𝑥 < 4.1.10 |
djangoproject | django | 4.2 ≤ 𝑥 < 4.2.3 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
debian | debian_linux | 12.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
python-django |
|
Common Weakness Enumeration
References