CVE-2024-27351Medium· 5.3▾ SunlitRegular expression denial-of-service in Django
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.9%
In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a potential regular expression denial-of-service attack via a crafted string. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232 and CVE-2023-43665.
django >= 3.2, < 3.2.25django >= 4.2, < 4.2.11django >= 5.0, < 5.0.3Upgrade to a patched release:
django 3.2.25django 4.2.11django 5.0.3Connected by shared product, vendor, weakness, or advisory.
CVE-2024-38875High· 7.5Django vulnerable to Denial of Service
CVE-2024-39614High· 7.5Django vulnerable to Denial of Service
CVE-2024-39330High· 7.5Django Path Traversal vulnerability
CVE-2024-45231Low· 3.7Django allows enumeration of user e-mail addresses
CVE-2024-24680High· 7.5An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2
CVE-2024-39329Medium· 5.3An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14