An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities.

Project Subscriptions

Vendors Products
Djangoproject Subscribe
Ansible Automation Platform Subscribe
Ansible Automation Platform Developer Subscribe
Discovery Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4006-1 python-django security update
EUVD EUVD EUVD-2024-0048 An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities.
Github GHSA Github GHSA GHSA-8498-2h75-472j Django denial-of-service in django.utils.html.strip_tags()
Ubuntu USN Ubuntu USN USN-7136-1 Django vulnerabilities
Ubuntu USN Ubuntu USN USN-7136-2 Django vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00173}

epss

{'score': 0.00194}


Fri, 28 Feb 2025 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:discovery:1::el9 cpe:/o:redhat:discovery:1.0::el9

Thu, 13 Feb 2025 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat ansible Automation Platform Developer
Redhat discovery
CPEs cpe:/a:redhat:ansible_automation_platform_developer:2.5::el8
cpe:/a:redhat:ansible_automation_platform_developer:2.5::el9
cpe:/o:redhat:discovery:1::el9
Vendors & Products Redhat ansible Automation Platform Developer
Redhat discovery

Tue, 31 Dec 2024 18:45:00 +0000

Type Values Removed Values Added
References

Tue, 17 Dec 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat ansible Automation Platform
CPEs cpe:/a:redhat:ansible_automation_platform:2.4::el8
cpe:/a:redhat:ansible_automation_platform:2.4::el9
cpe:/a:redhat:ansible_automation_platform:2.5::el8
cpe:/a:redhat:ansible_automation_platform:2.5::el9
Vendors & Products Redhat
Redhat ansible Automation Platform

Fri, 06 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Djangoproject
Djangoproject django
Weaknesses CWE-770
CPEs cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
Vendors & Products Djangoproject
Djangoproject django
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Fri, 06 Dec 2024 12:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in the Django Web Framework. The strip_tags() and stripbtags template filter may be vulnerable to a potential denial of service (DoS) in cases of a large sequence of nested incomplete HTML entities. An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities.
References

Thu, 05 Dec 2024 02:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in the Django Web Framework. The strip_tags() and stripbtags template filter may be vulnerable to a potential denial of service (DoS) in cases of a large sequence of nested incomplete HTML entities.
Title django: Potential denial-of-service in django.utils.html.strip_tags()
Weaknesses CWE-1169
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-12-31T18:03:11.347Z

Reserved: 2024-11-24T00:00:00

Link: CVE-2024-53907

cve-icon Vulnrichment

Updated: 2024-12-31T18:03:11.347Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-06T12:15:17.730

Modified: 2025-06-24T14:55:06.263

Link: CVE-2024-53907

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-12-04T00:00:00Z

Links: CVE-2024-53907 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses