Description
validators.URLValidator in Django 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
References (4)
Core 4
Core References
Third Party Advisory vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/201510-06
Vendor Advisory x_refsource_confirm
https://www.djangoproject.com/weblog/2015/jul/08/security-releases/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/75691
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1032820
Scores
EPSS
0.0297
EPSS Percentile
85.8%
Details
CWE
CWE-399
Status
published
Products (4)
djangoproject/django
1.8.0
djangoproject/django
1.8.1
djangoproject/django
1.8.2
pypi/Django
1.8a1 - 1.8.3PyPI
Published
Jul 14, 2015
Tracked Since
Feb 18, 2026