CVE-2024-24680

MEDIUM5.9EPSS 1.4%

Django denial-of-service attack in the intcomma template filter

Published: 2/7/2024Modified: 11/6/2025
Also known as:GHSA-xxj9-f6rv-m3x4BIT-django-2024-24680PYSEC-2024-28

Description

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
osvCVSS 3.1MEDIUM5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

References (21)