{"id":"PYSEC-2025-14","details":"An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, and django.views.i18n.set_language are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.","aliases":["BIT-django-2025-27556","CVE-2025-27556","GHSA-wqfg-m96j-85vm"],"modified":"2026-06-10T17:01:05.028607361Z","published":"2025-04-02T13:15:44Z","references":[{"type":"ARTICLE","url":"https://www.djangoproject.com/weblog/2025/apr/02/security-releases/"},{"type":"WEB","url":"https://docs.djangoproject.com/en/dev/releases/security/"},{"type":"WEB","url":"https://groups.google.com/g/django-announce"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/04/02/2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wqfg-m96j-85vm"}],"affected":[{"package":{"name":"django","ecosystem":"PyPI","purl":"pkg:pypi/django"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.1"},{"fixed":"5.1.8"},{"introduced":"5.0"},{"fixed":"5.0.14"}]}],"versions":["5.0","5.0.1","5.0.10","5.0.11","5.0.12","5.0.13","5.0.2","5.0.3","5.0.4","5.0.5","5.0.6","5.0.7","5.0.8","5.0.9","5.1","5.1.1","5.1.2","5.1.3","5.1.4","5.1.5","5.1.6","5.1.7"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/django/PYSEC-2025-14.yaml"}}],"schema_version":"1.7.5"}