PYSEC-2009-4

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/django/PYSEC-2009-4.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2009-4
Aliases
Published
2009-10-13T10:30:00Z
Modified
2024-02-08T22:27:02.093627Z
Summary
[none]
Details

Algorithmic complexity vulnerability in the forms library in Django 1.0 before 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a crafted (1) EmailField (email address) or (2) URLField (URL) that triggers a large amount of backtracking in a regular expression.

References

Affected packages

PyPI / django

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0
Fixed
1.0.4
Introduced
1.1
Fixed
1.1.1

Affected versions

1.*

1.0.1
1.0.2
1.0.3
1.1