CVE-2025-27556Allocation of Resources Without Limits or Throttling in Django

Severity
7.5HIGHNVD
CNA5.8
EPSS
0.2%
top 61.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 2

Description

An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, and django.views.i18n.set_language are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5djangoproject/django5.05.0.14+1
NVDdjangoproject/django5.05.0.14+1
PyPIdjangoproject/django5.05.0.14+1

🔴Vulnerability Details

4
GHSA
Django Potential Denial of Service (DoS) on Windows2025-04-02
CVEList
CVE-2025-27556: An issue was discovered in Django 52025-04-02
OSV
Django Potential Denial of Service (DoS) on Windows2025-04-02
OSV
CVE-2025-27556: An issue was discovered in Django 52025-04-02

📋Vendor Advisories

2
Red Hat
django: Django DoS Unicode Attack2025-04-02
Debian
CVE-2025-27556: python-django - An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NF...2025
CVE-2025-27556 — Djangoproject Django vulnerability | cvebase