CVE-2025-64460Medium▾ SunlitDjango is vulnerable to DoS via XML serializer text extraction
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.1%
An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27.
Algorithmic complexity in django.core.serializers.xml_serializer.getInnerText() allows a remote attacker to cause a potential denial-of-service attack triggering CPU and memory exhaustion via specially crafted XML input processed by the XML Deserializer.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Seokchan Yoon for reporting this issue.
django >= 5.2a1, < 5.2.9django >= 5.1a1, < 5.1.15django >= 4.2a1, < 4.2.27Upgrade to a patched release:
django 5.2.9django 5.1.15django 4.2.27Connected by shared product, vendor, weakness, or advisory.
CVE-2026-5766Medium· 5.3Django has an Improper Handling of Length Parameter Inconsistency
CVE-2025-13372Medium· 4.3Django is vulnerable to SQL injection in column aliases
CVE-2025-64458High· 7.5Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2024-56374Medium· 5.8Django has a potential denial-of-service vulnerability in IPv6 validation
CVE-2025-26699Medium· 5.0Django vulnerable to Allocation of Resources Without Limits or Throttling
CVE-2026-4292Low· 2.7Django vulnerable to privilege abuse in ModelAdmin.list_editable