The Vulnerability History Project
Vulnerabilities
Insights
Curate
Tags
All
Projects
CWEs
Languages
Lessons
Severities
Subsystems
More
News
Projects We Study
How to Contribute
By the Numbers
About Us
Toggle Theme
Warning: Our website does not support Internet Explorer, please use Edge instead.
[1.11.x] Fixed CVE-2019-14233 -- Prevented excessive HTMLParser recursion in strip_tags() when handling incomplete HTML entities.
Thanks to Guido Vranken for initial report.
by
Leland the Mouse 2019-07-15 10:00:06 UTC
commit 52479acce792ad80bb0f915f20b835f919993c72
Django
Fix
Super Slow Tag Stripping CVE-2019-14233
django/utils/html.py
+2
-2
docs/releases/1.11.23.txt
-17
tests/utils_tests/test_html.py
-2
expand_less