Django Product Security Update Advisory (CVE-2024-27351)

Overview

 

We have released an update to address a vulnerability in the Django product. users of affected versions are advised to update to the latest version.

 

Affected Products

 

Django 5.0

Django 4.2 versions

Django 3.2 versions

 

Resolved Vulnerabilities

 

Potential regular expression denial of service vulnerability in django.utils.text.Truncator.words() in the Django product (CVE-2024-27351)

 

Vulnerability Patches

 

Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

Django 5.0.3

Django 4.2.11

Django 3.2.25

 

Referenced Sites

 

[1] Django security releases issued: 5.0.3, 4.2.11, and 3.2.25

https://www.djangoproject.com/weblog/2024/mar/04/security-releases/