{"schema_version":"1.9.0","id":"GHSA-wqfg-m96j-85vm","published":"2025-04-02T15:31:37Z","modified":"2025-09-25T09:27:20.004567Z","aliases":["BIT-django-2025-27556","CVE-2025-27556","PYSEC-2025-14"],"summary":"Django Potential Denial of Service (DoS) on Windows ","details":"An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, and django.views.i18n.set_language are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.","affected":[{"package":{"name":"django","ecosystem":"PyPI","purl":"pkg:pypi/django"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0"},{"fixed":"5.0.14"}]}],"versions":["5.0","5.0.1","5.0.10","5.0.11","5.0.12","5.0.13","5.0.2","5.0.3","5.0.4","5.0.5","5.0.6","5.0.7","5.0.8","5.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-wqfg-m96j-85vm/GHSA-wqfg-m96j-85vm.json"}},{"package":{"name":"django","ecosystem":"PyPI","purl":"pkg:pypi/django"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.1"},{"fixed":"5.1.8"}]}],"versions":["5.1","5.1.1","5.1.2","5.1.3","5.1.4","5.1.5","5.1.6","5.1.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-wqfg-m96j-85vm/GHSA-wqfg-m96j-85vm.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-27556"},{"type":"WEB","url":"https://github.com/django/django/commit/2cb311f7b069723027fb5def4044d1816d7d2afd"},{"type":"WEB","url":"https://github.com/django/django/commit/39e2297210d9d2938c75fc911d45f0e863dc4821"},{"type":"WEB","url":"https://github.com/django/django/commit/8c6871b097b6c49d2a782c0d80d908bcbe2116f1"},{"type":"WEB","url":"https://github.com/django/django/commit/edc2716d01a6fdd84b173c02031695231bcee1f8"},{"type":"WEB","url":"https://docs.djangoproject.com/en/dev/releases/security"},{"type":"PACKAGE","url":"https://github.com/django/django"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2025-14.yaml"},{"type":"WEB","url":"https://groups.google.com/g/django-announce"},{"type":"WEB","url":"https://www.djangoproject.com/weblog/2025/apr/02/security-releases"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/04/02/2"}],"database_specific":{"cwe_ids":["CWE-770"],"github_reviewed":true,"github_reviewed_at":"2025-04-02T20:11:40Z","nvd_published_at":"2025-04-02T13:15:44Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L"}]}