CVE-2024-28865High· 7.5▾ TwilightDenial of service via regular expression
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.6%
0.6% → 0.6%
Last analysed / modified upstream
All historical installations of django-wiki are vulnerable to maliciously crafted article content, that can cause severe use of server CPU through a regular expression loop.
Close off access to create and edit articles by anonymous users.
Are there any links users can visit to find out more?
wiki < 0.10.1Upgrade to a patched release:
wiki 0.10.1