CVE-2026-1285 is a denial-of-service vulnerability affecting Django versions 6.0.x (before 6.0.2), 5.2.x (before 5.2.11), and 4.2.x (before 4.2.28). Remote attackers can exploit this by submitting crafted inputs with numerous unmatched HTML end tags to the Truncator.chars(), Truncator.words() methods, or associated template filters. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and a high impact on availability. There is no evidence of active exploitation, public exploit code, or inclusion in the CISA KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.2, < 4.2.28CPE match | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | ||
>= 5.2, < 5.2.11CPE match | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | ||
>= 6.0, < 6.0.2CPE match | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.