CVE-2026-25673
An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normalization on Windows that is disproportionately slow for certain Unicode…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normalization on Windows that is disproportionately slow for certain Unicode characters, allowing a remote attacker to cause denial of service via large URL inputs containing these characters. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.73% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400, CWE-770
- Affected
- djangoproject/django
- Source
- 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
References
- https://docs.djangoproject.com/en/dev/releases/security/Patch, Vendor Advisory
- https://groups.google.com/g/django-announceRelease Notes
- https://www.djangoproject.com/weblog/2026/mar/03/security-releases/Patch, Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-25673
- https://bugzilla.redhat.com/show_bug.cgi?id=2444115
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25673.json
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.