Moderate severityNVD Advisory· Published Mar 6, 2025· Updated Mar 19, 2025
CVE-2025-26699
CVE-2025-26699
Description
An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
DjangoPyPI | >= 4.2, < 4.2.20 | 4.2.20 |
DjangoPyPI | >= 5.0, < 5.0.13 | 5.0.13 |
DjangoPyPI | >= 5.1, < 5.1.7 | 5.1.7 |
Affected products
9- osv-coords8 versionspkg:apk/chainguard/awxpkg:bitnami/djangopkg:pypi/djangopkg:rpm/opensuse/python-Django4&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django6&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python-Django&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-Django&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6
< 24.6.1-r4+ 7 more
- (no CPE)range: < 24.6.1-r4
- (no CPE)range: >= 4.2.0, < 5.1.7
- (no CPE)range: >= 4.2, < 4.2.20
- (no CPE)range: < 4.2.20-1.1
- (no CPE)range: < 6.0-1.1
- (no CPE)range: < 4.2.11-150600.3.18.1
- (no CPE)range: < 5.1.7-1.1
- (no CPE)range: < 4.2.11-150600.3.18.1
- Range: 4.2
Patches
Vulnerability mechanics
References
10- github.com/advisories/GHSA-p3fp-8748-vqfqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-26699ghsaADVISORY
- www.openwall.com/lists/oss-security/2025/03/06/12ghsaWEB
- docs.djangoproject.com/en/dev/releases/securityghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2025-13.yamlghsaWEB
- groups.google.com/g/django-announceghsaWEB
- lists.debian.org/debian-lts-announce/2025/03/msg00012.htmlghsaWEB
- www.djangoproject.com/weblog/2025/mar/06/security-releasesghsaWEB
- docs.djangoproject.com/en/dev/releases/security/mitre
- www.djangoproject.com/weblog/2025/mar/06/security-releases/mitre
News mentions
0No linked articles in our index yet.