CVE-2019-14232 is a denial-of-service vulnerability affecting Django versions 1.11.x, 2.1.x, and 2.2.x, specifically within the truncatechars_html and truncatewords_html template filters. This flaw stems from catastrophic backtracking in a regular expression used by the chars() and words() methods when processing HTML input, leading to extremely slow evaluation. Rated with a CVSS score of 7.5 (High), this vulnerability can be exploited remotely with low attack complexity, resulting in a high impact on availability (A:H). There is no confidentiality or integrity impact. Currently, there is no evidence of active exploitation (KEV: No), nor are there public exploit modules available in Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered some community discussion and media coverage, indicating a degree of awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.11, < 1.11.23CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | ||
>= 2.1, < 2.1.11CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | ||
>= 2.2, < 2.2.4CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.