Logo
vulnerabilityCVE-2025-32873
Name
CVE-2025-32873
Source
NVD ( link)Debian ( link)
Description
An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().
Published Date
Updated Date
Workaround
-

Analysis#


Vulnerability Ratings#


5.3
CVSSv31
5.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
6.0.6
Not Affected
yocto
scarthgap
4.2.30
Not Affected

Resolved with patches#


python3-django (yocto:kirkstone)

#
Title
Author
Resolve
1
Fixed CVE-2025-32873 -- Mitigated potential DoS in
Marc Deslauriers <marc.deslauriers@ubuntu.com>
CVE-2025-32873

python3-django (yocto:kirkstone)

#
Title
Author
Resolve
1
Fixed CVE-2025-32873 -- Mitigated potential DoS in
Marc Deslauriers <marc.deslauriers@ubuntu.com>
CVE-2025-32873

python3-django (yocto:kirkstone)

#
Title
Author
Resolve
1
Fixed CVE-2025-32873 -- Mitigated potential DoS in
Marc Deslauriers <marc.deslauriers@ubuntu.com>
CVE-2025-32873