Related Vulnerabilities: CVE-2019-14235  

If passed certain inputs, django.utils.encoding.uri_to_iri() could lead to significant memory usage due to excessive recursion when re-percent encoding invalid UTF-8 octet sequences.

Severity Medium

Remote Yes

Type Denial of service

Description

If passed certain inputs, django.utils.encoding.uri_to_iri() could lead to significant memory usage due to excessive recursion when re-percent encoding invalid UTF-8 octet sequences.

AVG-1015 python-django 2.2.3-1 Medium Vulnerable

AVG-1014 python2-django 1.11.22-1 Medium Vulnerable

https://github.com/django/django/commit/76ed1c49f804d409cfc2911a890c78584db3c76e