Severity
7.5HIGHNVD
EPSS
0.1%
top 79.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 3
Latest updateApr 13

Description

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.chars()` and `Truncator.words()` methods (with `html=True`) and the `truncatechars_html` and `truncatewords_html` template filters allow a remote attacker to cause a potential denial-of-service via crafted inputs containing a large number of unmatched HTML end tags. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Dja

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5djangoproject/django6.06.0.2+2
NVDdjangoproject/django4.24.2.28+2
PyPIdjangoproject/django6.0a16.0.2+2

Patches

🔴Vulnerability Details

4
OSV
CVE-2026-1285: An issue was discovered in 62026-02-03
OSV
Django has Inefficient Algorithmic Complexity2026-02-03
CVEList
Potential denial-of-service vulnerability in django.utils.text.Truncator HTML methods2026-02-03
GHSA
Django has Inefficient Algorithmic Complexity2026-02-03

📋Vendor Advisories

22
Red Hat
ImageMagick: Magick.NET: ImageMagick: Denial of service via heap out-of-bounds write in JP2 encoder2026-04-13
Red Hat
FFmpeg: FFmpeg: Denial of Service via out-of-bounds read2026-04-13
Red Hat
wasmtime: Wasmtime: Denial of Service via WebAssembly compilation error2026-04-09
Red Hat
kernel: media: dvb-net: fix OOB access in ULE extension header tables2026-04-06
Red Hat
kernel: net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check2026-04-03

🕵️Threat Intelligence

1
Wiz
CVE-2026-1285 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-1285 — Inefficient Algorithmic Complexity | cvebase