7.5
CVSSv3

CVE-2023-36053

Published: 03/07/2023 Updated: 20/04/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

In Django 3.2 prior to 3.2.20, 4 prior to 4.1.10, and 4.2 prior to 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

djangoproject django

debian debian linux 10.0

debian debian linux 11.0

debian debian linux 12.0

fedoraproject fedora 37

fedoraproject fedora 38

Vendor Advisories

Debian Bug report logs - #1040225 python-django: CVE-2023-36053 Package: python-django; Maintainer for python-django is Debian Python Team <team+python@trackerdebianorg>; Source for python-django is src:python-django (PTS, buildd, popcon) Reported by: "Chris Lamb" <lamby@debianorg> Date: Mon, 3 Jul 2023 16:27:01 ...
Synopsis Moderate: Red Hat Ansible Automation Platform 24 Product Security and Bug Fix Update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat Ansible Automation Platform 24Red Hat P ...
Synopsis Moderate: Red Hat Ansible Automation Platform 24 Product Security and Bug Fix Update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat Ansible Automation Platform 24Red Hat P ...
Seokchan Yoon discovered that missing sanitising in the email and URL validators of Django, a Python web development framework, could result in denial of service For the oldstable distribution (bullseye), this problem has been fixed in version 2:2228-1~deb11u2 This update also addresses CVE-2023-23969, CVE-2023-31047 and CVE-2023-24580 For the ...

Github Repositories

PROFILE Seokchan Yoon (@ch4n3yoon) ch4n3yoon@gmailcom A CTF player of STEALIEN and Aleph Infinite Web Security Researcher @ STEALIEN (202007 ~ 202306) ACHIEVEMENT/AWARDS Finalist, CODEGATE 2023 UNIVERSITY (team: 경희대미남해커들) Finalist, CODEGATE 2022 UNIVERSITY (team: 경희대미남해커들) Finalist (2nd, 국가보안연구소장상), 2022 사이버공