CVE-2025-27556 Information

Description

An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence django.contrib.auth.views.LoginView django.contrib.auth.views.LogoutView and django.views.i18n.set_language are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.

Reference

http://www.openwall.com/lists/oss-security/2025/04/02/2 https://docs.djangoproject.com/en/dev/releases/security/ https://groups.google.com/g/django-announce https://www.djangoproject.com/weblog/2025/apr/02/security-releases/

Share on: