CVE-2026-25673Disclosure(djangoproject / django)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch djangoproject django systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normalization on Windows that is disproportionately slow for certain Unicode characters, allowing a remote attacker to cause denial of service via large URL inputs containing these characters. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • django

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-03); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
django

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-03: 3Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Mentions · 2026-03-08: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-08: 1Technical Details · 2026-03-03: 3Technical Details · 2026-03-04: 1Technical Details · 2026-03-08: 103-0303-0403-0503-08
Signal classification3 categories
Disclosure
233.3%
General
233.3%
Patch
233.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-033
Disclosure2General1
2026-03-041
Patch1
2026-03-051
General1
2026-03-081
Patch1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Patch

    Django releases security updates (6.0.3, 5.2.12, 4.2.29) to fix a Windows DoS flaw (CVE-2026-25673) and file permission risks. Upgrade your framework now. #Django #CyberSecurity #CVE202625673 #Python #WebDev #InfoSec #PatchAlert #Vulnerability #AppSec https://securityonline.info/django-releases-security-patches-to-address-dos-and-permission-vulnerabilities/

    Post summary

    Django has released specific patch versions to address a Windows DoS vulnerability (CVE-2026-25673) and file permission issues; users are urged to upgrade immediately.

    02052284
    10.5K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    2 CVEs fixed in Django https://www.openwall.com/lists/oss-security/2026/03/03/3 CVE-2026-25673: DoS in URLField via Unicode normalization on Windows CVE-2026-25674: Potential incorrect permissions on newly created file system objects in multi-threaded environments

    Post summary

    The message announces that Django has fixed CVE‑2026‑25673 (DoS via Unicode normalization) and CVE‑2026‑25674 (incorrect file permissions), providing brief technical details and linking to a vendor advisory.

    00020323
    4.4K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Django ❗ CVE-2026-25673 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-django-2/ https://t.co/1VEvxvmW2i

    Post summary

    The tweet announces a new Django-related vulnerability (CVE-2026-25673) and directs readers to an external resource for additional information.

    00001128
    6.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25673 Django URL Parsing Denial of Service Vulnerability in Multiple Versions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25673 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A new Django URL parsing DoS vulnerability (CVE-2026-25673) has been identified, with links to details and a notification, but no PoC, exploit, patch, or active exploitation information is provided.

    0001065
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25673 An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `http://URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which perform… https://www.cve.org/CVERecord?id=CVE-2026-25673 ----- Traducción: CVE-2026-25673 Se descubrió un …

    Post summary

    The post announces CVE-2026-25673, detailing affected Django versions and a technical detail about URLField.to_python() calling urllib.parse.urlsplit(), but provides no PoC, exploit, or patch information.

    0001030
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25673 An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `http://URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which perform… https://www.cve.org/CVERecord?id=CVE-2026-25673

    Post summary

    The text announces a vulnerability in Django’s URLField.to_python method affecting multiple major releases, providing affected version ranges and a reference to the CVE record.

    00010221
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdjangoprojectdjango---

Explore more