CVE-2019-6975 is an uncontrolled memory consumption vulnerability affecting the Django web framework versions 1.11.x, 2.0.x, and 2.1.x prior to their respective security updates. Rated as High severity with a CVSS score of 7.5, this flaw allows unauthenticated remote attackers to trigger a denial of service by supplying malicious values to the django.utils.numberformat.format() function. Despite a FAUCET risk score of 86, there is currently no evidence of active exploitation, no public exploit code available in repositories like Metasploit or ExploitDB, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.11.0, < 1.11.19CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | ||
>= 2.0.0, < 2.0.11CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | ||
>= 2.1.0, < 2.1.6CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.