CVE-2022-41323

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/10/2022
Last modified:
14/05/2025

Description

In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* 3.2 (including) 3.2.16 (excluding)
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* 4.0 (including) 4.0.8 (excluding)
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* 4.1 (including) 4.1.2 (excluding)


References to Advisories, Solutions, and Tools