The Django team is releasing security updates for Django 5.1.7, 5.0.13, and 4.2.20 to address potential security issues. The releases fix a denial-of-service vulnerability in the django.utils.text.wrap() function and wordwrap template filter when used with very long strings. This issue has a moderate severity rating according to Django's security policy. The vulnerability affects Django versions 5.2, 5.1, 5.0, and 4.2. Patches have been applied to resolve the issue, and the releases can be downloaded from the Django website. The patches can also be obtained from the changesets on the main, 5.2, 5.1, 5.0, and 4.2 branches. Users are encouraged to upgrade as soon as possible. The security issue was reported by sw0rd1ight. The releases were signed with the PGP key ID of Sarah Boyce. The Django team reminds users to report potential security issues via private email to security@djangoproject.com, rather than through the Django Trac instance or forum.
djangoproject.com
djangoproject.com
Create attached notes ...
