VDB
Sign up
—

PYSEC-2025-1

Quick fix

PYSEC-2025-1 — django: upgrade to the fixed version with the command below.

pip install --upgrade 'django>=4.2.18'

Details

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/django
Introduced in: 5.1Fixed in: 5.1.5
Fixpip install --upgrade 'django>=4.2.18'

References