Django is vulnerable to a denial-of-service attack due to slow NFKC normalization on Windows in `django.contrib.auth.views.LoginView`, `django.contrib.
more...
Django is vulnerable to a denial-of-service attack due to slow NFKC normalization on Windows in `django.contrib.auth.views.LoginView`, `django.contrib.auth.views.LogoutView`, and `django.views.i18n.set_language`. This could allow an attacker to exploit the vulnerability by sending inputs with a very large number of Unicode characters, potentially leading to service disruption.
**Note: The authoring of this BDSA has been AI-assisted. The full technical details of the vulnerability have not been independently verified by the Black Duck Cybersecurity Research Center (CyRC).**
less...
This site uses cookies to give you the best possible experience.
By using the site, you consent to our use of cookies.
For more information, please see our
Privacy Policy