CVE-2024-39614High· 7.5▾ MidnightPoC availableDjango vulnerable to Denial of Service
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 5.7 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
29%
1 GitHub repo (last check)
An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings containing specific characters.
django >= 5.0, < 5.0.7django >= 4.2, < 4.2.14Upgrade to a patched release:
django 5.0.7django 4.2.14Connected by shared product, vendor, weakness, or advisory.
CVE-2024-38875High· 7.5Django vulnerable to Denial of Service
CVE-2024-39330High· 7.5Django Path Traversal vulnerability
CVE-2024-45231Low· 3.7Django allows enumeration of user e-mail addresses
CVE-2025-64458High· 7.5Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2025-32873Medium· 5.3Django has a denial-of-service possibility in strip_tags()
CVE-2025-57833High· 7.1Django is subject to SQL injection through its column aliases