icon

We found results for “

CVE-2025-32873

Good to know:

icon
icon

Date: May 7, 2025

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().

Severity Score

Severity Score

Weakness Type (CWE)

Allocation of Resources Without Limits or Throttling

CWE-770

Top Fix

icon

Upgrade Version

Upgrade to version Django - 4.2.21;Django - 5.1.9;Django - 5.2.1;django - 4.2.21;django - 5.1.9;django - 5.2.1;django - 5.2.1;https://github.com/django/django.git - 4.2.21;https://github.com/django/django.git - 5.1.9;https://github.com/django/django.git - 5.2.1

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): LOW

Do you need more information?

Contact Us