HIGH7.5
PYSEC-2026-2049
Denial of service via regular expression
Quick fix
PYSEC-2026-2049 — wiki: upgrade to the fixed version with the command below.
pip install --upgrade 'wiki>=0.10.1'Details
### Impact
All historical installations of django-wiki are vulnerable to maliciously crafted article content, that can cause severe use of server CPU through a regular expression loop.
### Patches
### Workarounds
Close off access to create and edit articles by anonymous users.
### References _Are there any links users can visit to find out more?_
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/django-wiki/django-wiki/security/advisories/GHSA-wj85-w4f4-xh8h[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-28865[ADVISORY]
- https://github.com/django-wiki/django-wiki/commit/8e280fd6c0bd27ce847c67b2d216c6cbf920f88c[WEB]
- https://github.com/django-wiki/django-wiki[PACKAGE]
- https://pypi.org/project/wiki[PACKAGE]
- https://github.com/advisories/GHSA-wj85-w4f4-xh8h[ADVISORY]