In-app reader
__ CVE-2026-25673 Detail
** Modified After Enrichment **
This CVE record has been updated after NVD enrichment efforts were completed. Enrichment data supplied by the NVD may require amendment due to these changes.
An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29.
URLField.to_python() in Django calls urllib.parse.urlsplit(), which performs NFKC normalization on Windows that is disproportionately slow for certain Unicode characters, allowing a remote attacker to cause denial of service via large URL inputs containing these characters.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Seokchan Yoon for reporting this issue.
**CVSS Version 4.0
**CVSS Version 3.x
**CVSS Version 2.0
_
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
_
CVSS 4.0 Severity and Vector Strings:
NIST: NVD
** ** N/A
NVD assessment not yet provided. _
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base Score: N/A
NVD assessment not yet provided. _
ADP: CISA-ADP
Base Score: 7.5 HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H _
ADP: redhat-SADP
Base Score: 7.5 HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H _
CVSS 2.0 Severity and Vector Strings:
NIST: NVD
Base Score: N/A
NVD assessment not yet provided. _
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].
URL Source(s) Tag(s)
https://access.redhat.com/security/cve/CVE-2026-25673
redhat-SADP
https://bugzilla.redhat.com/show_bug.cgi?id=2444115
redhat-SADP
https://docs.djangoproject.com/en/dev/releases/security/
Django Software Foundation
Patch
Vendor Advisory
https://groups.google.com/g/django-announce
Django Software Foundation
Release Notes
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25673.json
redhat-SADP
https://www.djangoproject.com/weblog/2026/mar/03/security-releases/
Django Software Foundation
Patch
Vendor Advisory
CWE-ID CWE Name Source
Allocation of Resources Without Limits or Throttling
NIST
redhat-SADP
Uncontrolled Resource Consumption
Django Software Foundation
Known Affected Software Configurations Switch to CPE 2.2
_
_ _
__ Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
7 change records found show changes
** CVE Modified by redhat-SADP 7/14/2026 10:18:56 PM **
Action Type Old Value New Value
Changed Affected
[{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Discovery 2","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:discovery:2::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:satellite:6"]}]
Record truncated, showing 2048 of 3478 characters.
View Entire Change Record
[{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-automation-platform-24/lightspeed-rhel8","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-automation-platform-25/lightspeed-rhel8","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-automation-platform-26/controller-rhel9","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-automation-platform-26/eda-controller-rhel9","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-automation-platform-26/gateway-rhel9","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-automation-platform-26/hub-rhel9","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-automation-platform-26/lightspeed-rhel9","cpes":["cpe:/a:redhat:
CVE Modified by redhat-SADP 6/29/2026 11:17:43 PM
Action Type Old Value New Value
Added CVSS V3.1
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Added CWE
CWE-770
Added Reference
https://access.redhat.com/security/cve/CVE-2026-25673
Added Reference
https://bugzilla.redhat.com/show_bug.cgi?id=2444115
Added Reference
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25673.json
Added Affected
[{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Discovery 2","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:discovery:2::el9"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:satellite:6"]}]
CVE Modified by CISA-ADP 6/17/2026 6:25:02 AM
Action Type Old Value New Value
Added SSVC
{"timestamp":"2026-03-03T15:25:53.980126Z","id":"CVE-2026-25673","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}
CVE Modified by Django Software Foundation 6/17/2026 6:25:02 AM
Action Type Old Value New Value
Added Affected
[{"vendor":"djangoproject","product":"Django","defaultStatus":"unaffected","collectionURL":"https://pypi.org/project/Django/","packageName":"django","repo":"https://github.com/django/django/","versions":[{"version":"6.0","lessThan":"6.0.3","versionType":"semver","status":"affected"},{"version":"6.0.3","versionType":"semver","status":"unaffected"},{"version":"5.2","lessThan":"5.2.12","versionType":"semver","status":"affected"},{"version":"5.2.12","versionType":"semver","status":"unaffected"},{"version":"4.2","lessThan":"4.2.29","versionType":"semver","status":"affected"},{"version":"4.2.29","versionType":"semver","status":"unaffected"}]}]
Initial Analysis by NIST 3/05/2026 9:12:38 AM
Action Type Old Value New Value
Added CWE
CWE-770
Added CPE Configuration
OR
*cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* versions from (including) 4.2.0 up to (excluding) 4.2.29
*cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* versions from (including) 5.2 up to (excluding) 5.2.12
*cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* versions from (including) 6.0 up to (excluding) 6.0.3
Added Reference Type
Django Software Foundation: https://docs.djangoproject.com/en/dev/releases/security/ Types: Patch, Vendor Advisory
Added Reference Type
Django Software Foundation: https://groups.google.com/g/django-announce Types: Release Notes
Added Reference Type
Django Software Foundation: https://www.djangoproject.com/weblog/2026/mar/03/security-releases/ Types: Patch, Vendor Advisory
CVE Modified by CISA-ADP 3/03/2026 11:16:20 AM
Action Type Old Value New Value
Added CVSS V3.1
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
New CVE Received from Django Software Foundation 3/03/2026 10:16:19 AM
Action Type Old Value New Value
Added Description
An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29.
`URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normalization on Windows that is disproportionately slow for certain Unicode characters, allowing a remote attacker to cause denial of service via large URL inputs containing these characters.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Seokchan Yoon for reporting this issue.
Added CWE
CWE-400
Added Reference
https://docs.djangoproject.com/en/dev/releases/security/
Added Reference
https://groups.google.com/g/django-announce
Added Reference
https://www.djangoproject.com/weblog/2026/mar/03/security-releases/
Quick Info
CVE Dictionary Entry: CVE-2026-25673 NVD Published Date: 03/03/2026 NVD Last Modified: 07/14/2026 ** Source:** Django Software Foundation
_
Discussion
Sign in to join the discussion.
Keep reading
Optional: create a free account to save items, track programs, and sync across web + app. Reading stays free.