CVE Vulnerabilities

CVE-2024-41989

Published: Aug 07, 2024 | Modified: Nov 04, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given a string representation of a number in scientific notation with a large exponent.

Affected Software

NameVendorStart VersionEnd Version
DjangoDjangoproject4.2 (including)4.2.15 (excluding)
DjangoDjangoproject5.0 (including)5.0.8 (excluding)
Discovery 1 for RHEL 9RedHatdiscovery/discovery-server-rhel9:1.12.0-1*
Discovery 1 for RHEL 9RedHatdiscovery/discovery-ui-rhel9:1.12.0-1*
Red Hat Ansible Automation Platform 2.4 for RHEL 8RedHatpython3x-django-0:4.2.15-1.el8ap*
Red Hat Ansible Automation Platform 2.4 for RHEL 9RedHatpython-django-0:4.2.15-1.el9ap*
Red Hat Ansible Automation Platform 2.5 for RHEL 8RedHatautomation-controller-0:4.6.2-1.el8ap*
Red Hat Ansible Automation Platform 2.5 for RHEL 9RedHatautomation-controller-0:4.6.2-1.el9ap*
RHUI 4 for RHEL 8RedHatpython-django-0:4.2.15-1.el8ui*
Python-djangoUbuntudevel*
Python-djangoUbuntuesm-infra/bionic*
Python-djangoUbuntuesm-infra/focal*
Python-djangoUbuntufocal*
Python-djangoUbuntujammy*
Python-djangoUbuntunoble*
Python-djangoUbuntuoracular*
Python-djangoUbuntuplucky*
Python-djangoUbuntuquesting*
Python-djangoUbuntutrusty/esm*
Python-djangoUbuntuupstream*

References