GHSA-jh3w-4vvf-mjgr
GitHub Security Advisory
Django has regular expression denial of service vulnerability in EmailValidator/URLValidator
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, `EmailValidator` and `URLValidator` are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
Affected Packages
PyPI
Django
Affected versions:
3.2a1
(fixed in 3.2.20)
PyPI
Django
Affected versions:
4.0a1
(fixed in 4.1.10)
PyPI
Django
Affected versions:
4.2a1
(fixed in 4.2.3)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: September 9, 2025 6:37 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.