HIGH Score: 7.5/10

Vulnerability Summary

An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is slow on Windows. As a consequence, `django.http.HttpResponseRedirect`, `django.http.HttpResponsePermanentRedirect`, and the shortcut `django.shortcuts.redirect` were subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.

Technical Analysis

  • CVE ID: CVE-2025-64458
  • Published: 2025-11-05T15:15:40.940
  • Status: Active

How to Fix & Protect

The primary mitigation is to update the affected software immediately. Check the vendor's official security advisory for the latest patch.

Mitigation: If a patch is not available, restrict network access to the vulnerable component or disable the service.

Sponsored Stories