Allocation of Resources Without Limits or Throttling Affecting django package, versions [,4.2.21)[5.0a1,5.1.9)[5.2a1,5.2.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.01% (2nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-DJANGO-10074036
  • published8 May 2025
  • disclosed8 May 2025
  • creditElias Myllymäki

Introduced: 8 May 2025

NewCVE-2025-32873  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade Django to version 4.2.21, 5.1.9, 5.2.1 or higher.

Overview

Django is a high-level Python Web framework that encourages rapid development and clean, pragmatic design.

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling through the strip_tags() function. An attacker can cause slow performance by supplying large sequences of incomplete HTML tags.

Note: This also affects the striptags template filter which is built on top of strip_tags()

CVSS Base Scores

version 4.0
version 3.1