CVE-2023-36053: Django has regular expression denial of service vulnerability in EmailValidator/URLValidator
(updated )
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator
and URLValidator
are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
References
- docs.djangoproject.com/en/4.2/releases/security
- github.com/advisories/GHSA-jh3w-4vvf-mjgr
- github.com/django/django
- github.com/django/django/commit/454f2fb93437f98917283336201b4048293f7582
- github.com/django/django/commit/ad0410ec4f458aa39803e5f6b9a3736527062dcd
- github.com/django/django/commit/b7c5feb35a31799de6e582ad6a5a91a9de74e0f9
- github.com/django/django/commit/beb3f3d55940d9aa7198bf9d424ab74e873aec3d
- github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2023-100.yaml
- groups.google.com/forum/
- groups.google.com/forum/
- lists.debian.org/debian-lts-announce/2023/07/msg00022.html
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NRDGTUN4LTI6HG4TWR3JYLSFVXPZT42A
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XG5DYKPNDCEHJQ3TKPJQO7QGSR4FAYMS
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NRDGTUN4LTI6HG4TWR3JYLSFVXPZT42A
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XG5DYKPNDCEHJQ3TKPJQO7QGSR4FAYMS
- nvd.nist.gov/vuln/detail/CVE-2023-36053
- www.debian.org/security/2023/dsa-5465
- www.djangoproject.com/weblog/2023/jul/03/security-releases
Detect and mitigate CVE-2023-36053 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →