id: PYSEC-2022-304 details: In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression. affected: - package: name: django ecosystem: PyPI purl: pkg:pypi/django ranges: - type: GIT repo: https://github.com/django/django events: - introduced: "0" - fixed: 5b6b257fa7ec37ff27965358800c67e2dd11c924 - type: ECOSYSTEM events: - introduced: "3.2" - fixed: 3.2.16 - introduced: "4.0" - fixed: 4.0.8 - introduced: "4.1" - fixed: 4.1.2 versions: - "3.2" - 3.2.1 - 3.2.10 - 3.2.11 - 3.2.12 - 3.2.13 - 3.2.14 - 3.2.15 - 3.2.2 - 3.2.3 - 3.2.4 - 3.2.5 - 3.2.6 - 3.2.7 - 3.2.8 - 3.2.9 - "4.0" - 4.0.1 - 4.0.2 - 4.0.3 - 4.0.4 - 4.0.5 - 4.0.6 - 4.0.7 - "4.1" - 4.1.1 references: - type: WEB url: https://docs.djangoproject.com/en/4.0/releases/security/ - type: FIX url: https://github.com/django/django/commit/5b6b257fa7ec37ff27965358800c67e2dd11c924 - type: ARTICLE url: https://www.djangoproject.com/weblog/2022/oct/04/security-releases/ - type: WEB url: https://groups.google.com/forum/#!forum/django-announce - type: ADVISORY url: https://github.com/advisories/GHSA-qrw5-5h28-6cmg aliases: - CVE-2022-41323 - GHSA-qrw5-5h28-6cmg modified: "2022-10-16T10:47:15.418796Z" published: "2022-10-16T06:15:00Z"