Django is vulnerable to Denial of Service (DoS)
59
Medium Risk
GeoDjango's GEOSGeometry parses text and binary geometry input, including nested GEOMETRYCOLLECTION objects. Deeply nested collections trigger unbounded recursion in the underlying GEOS library and cause a segmentation fault that crashes the process. The fix enforces a maximum of 198 nested geometry collections for the WKT and WKB formats.
You are affected if you are using a version that falls within the vulnerable range and your application parses untrusted geometry input through GeoDjango.
Django is vulnerable to Denial of Service (DoS) in versions 5.2.0 - 5.2.16 and 6.0.0 - 6.0.7.
Upgrade the Django library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant