CVE-2025-26699
CVE-2025-26699
Título es
CVE-2025-26699
Jue, 06/03/2025 – 19:15
Tipo
CWE-770
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-26699
Descripción en
An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.
06/03/2025
06/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
Gravedad 3.1 (CVSS 3.1 Base Score)
5.00
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
https://docs.djangoproject.com/en/dev/releases/security/
https://groups.google.com/g/django-announce
https://www.djangoproject.com/weblog/2025/mar/06/security-releases/
http://www.openwall.com/lists/oss-security/2025/03/06/12
Enviar en el boletín
Off
