← All CVEs

CVE-2023-46695

high · 7.5

An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.forms.UsernameField is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.

7.5
CVSS
49.8%
EPSS (exploit prob.)
99th
EPSS percentile
2023-11-02
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-770

Affected products

VendorProductAffected versions
djangoprojectdjango>= 3.2, < 3.2.23
djangoprojectdjango>= 4.1, < 4.1.13
djangoprojectdjango>= 4.2., < 4.2.7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-46695