#VU82638 Resource exhaustion in Django - CVE-2023-46695
Published: November 1, 2023
Django
Django Software Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources during NFKC normalization. A remote attacker can pass a very large number of Unicode characters to "django.contrib.auth.forms.UsernameField" and perform a denial of service (DoS) attack.
The vulnerability affects Windows installations only.