Description
An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normalization on Windows that is disproportionately slow for certain Unicode characters, allowing a remote attacker to cause denial of service via large URL inputs containing these characters. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.
INFO
Published Date :
2026-03-03T14:28:28.601Z
Last Modified :
2026-03-03T15:26:02.764Z
Source :
DSF
AFFECTED PRODUCTS
The following products are affected by CVE-2026-25673 vulnerability.
| Vendors | Products |
|---|---|
| Djangoproject |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-25673.