CVE-2022-41323Regex Denial of Service in Django

Severity
7.5HIGHNVD
EPSS
7.9%
top 7.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 16

Description

In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDdjangoproject/django3.23.2.16+2
PyPIdjangoproject/django3.23.2.16+2

Patches

🔴Vulnerability Details

4
GHSA
Django denial-of-service vulnerability in internationalized URLs2022-10-16
OSV
CVE-2022-41323: In Django 32022-10-16
OSV
Django denial-of-service vulnerability in internationalized URLs2022-10-16
CVEList
CVE-2022-41323: In Django 32022-10-16

📋Vendor Advisories

3
Ubuntu
Django vulnerability2022-10-04
Red Hat
python-django: Potential denial-of-service vulnerability in internationalized URLs2022-10-04
Debian
CVE-2022-41323: python-django - In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internation...2022
CVE-2022-41323 — Regex Denial of Service in Django | cvebase