CVE-2025-32873 log

Source
Severity Medium
Remote Yes
Type Denial of service
Description
django.utils.html.strip_tags() would be slow to evaluate certain inputs containing large sequences of incomplete HTML tags. This function is used to implement the striptags template filter, which was thus also vulnerable. django.utils.html.strip_tags() now raises a SuspiciousOperation exception if it encounters an unusually large number of unclosed opening tags.
Group Package Affected Fixed Severity Status Ticket
AVG-2876 python-django 5.1.8-1 5.1.9-1 Medium Fixed
Date Advisory Group Package Severity Type
19 May 2025 ASA-202505-10 AVG-2876 python-django Medium denial of service
References
https://www.djangoproject.com/weblog/2025/may/07/security-releases/