CVE-2024-39614
26Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 29%
exploitation probability
29%top 2% of all CVEs
observed exploitation
nono source reports it
In short
Django's language detection function can be overwhelmed by specially crafted long text strings, causing the application to become unresponsive or slow down significantly. This allows attackers to disrupt service without needing special permissions.
Technical detail
The get_supported_language_variant() function in Django 5.0 (<5.0.7) and 4.2 (<4.2.14) is vulnerable to ReDoS (Regular Expression Denial of Service) or algorithmic complexity attacks when processing excessively long strings with specific character patterns. The attack requires no authentication and can be triggered via language preference inputs, resulting in CPU exhaustion and denial of service.
Summary generated and translated by AI from the official description.
An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings containing specific characters.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
n/a · n/a