Description
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
Remediation
References
Related Vulnerabilities
Liferay DXP Incorrect Default Permissions Vulnerability (CVE-2022-42128)
WordPress Plugin Google Sitemap by BestWebSoft Cross-Site Scripting (3.0.7)
phpMyAdmin URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-1000013)
Serendipity Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2011-1134)