Skip to main content
aeolus
  • Source
  • Home
  • Browse
    by section by tag by source
  • Events
  • Archive
  • RSS feed

[ASA-202505-10] python-django: denial of service

Arch

2025-05-19 23:13

Source

Original site

A remote attacker can exploit inefficient HTML tag parsing in Django’s strip_tags() function to cause excessive CPU usage, leading to a denial of service. This may affect applications that use the striptags template filter to sanitize user-controlled input, making them vulnerable to slowdown or unresponsiveness when handling specially crafted HTML content.
  • Previous post
  • Next post
Contents © 2025 elliot - Powered by Nikola