VDB
Sign up
—

PYSEC-2023-100

Quick fix

PYSEC-2023-100 — django: upgrade to the fixed version with the command below.

pip install --upgrade 'django>=3.2.20'

Details

In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/django
Introduced in: 4.2Fixed in: 4.2.3
Fixpip install --upgrade 'django>=3.2.20'

References