CVE-2025-64458
An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is slow on Windows. As a consequence, `django.http.HttpResponseRedirect`, `django.http.HttpResponsePermanentRedirect`, and the shortcut `django.shortcuts.redirect` were subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 1.90%
- CWE
- CWE-407
- Published
- 2025-11-05
- Last modified
- 2026-09-17
Affected products
- djangoproject Django
- djangoproject Django
- djangoproject Django
- djangoproject Django
- djangoproject Django
- djangoproject Django
Weakness type
Related vulnerabilities
- CVE-2022-36021 — Redis string pattern matching can be abused to achieve Denial of Service
- CVE-2026-34573 — Parse Server: GraphQL complexity validator exponential fragment traversal DoS
- CVE-2025-64460 — Potential denial-of-service vulnerability in XML serializer text extraction
- CVE-2026-1285 — Potential denial-of-service vulnerability in django.utils.text.Truncator HTML methods
- CVE-2025-14550 — Potential denial-of-service vulnerability via repeated headers when using ASGI
- CVE-2026-3276 — Potential DoS via quadratic complexity in unicodedata.normalize()
- CVE-2024-8233 — Inefficient Algorithmic Complexity in GitLab
- CVE-2022-22153 — SRX Series and MX Series with SPC3: A high percentage of fragments might lead to high latency or packet drops