In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2:2.2.12-1ubuntu0.14", "binary_name": "python-django-doc" }, { "binary_version": "2:2.2.12-1ubuntu0.14", "binary_name": "python3-django" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2:3.2.12-2ubuntu1.3", "binary_name": "python-django-doc" }, { "binary_version": "2:3.2.12-2ubuntu1.3", "binary_name": "python3-django" } ] }