{"id":"CVE-2024-28865","summary":"django-wiki denial of service via regular expression","details":"django-wiki is a wiki system for Django. Installations of django-wiki prior to version 0.10.1 are vulnerable to maliciously crafted article content that can cause severe use of server CPU through a regular expression loop. Version 0.10.1 fixes this issue. As a workaround, close off access to create and edit articles by anonymous users.","aliases":["GHSA-wj85-w4f4-xh8h"],"modified":"2026-04-10T05:11:35.783233Z","published":"2024-03-18T21:53:59.877Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/28xxx/CVE-2024-28865.json","cwe_ids":["CWE-1333"],"cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/28xxx/CVE-2024-28865.json"},{"type":"ADVISORY","url":"https://github.com/django-wiki/django-wiki/security/advisories/GHSA-wj85-w4f4-xh8h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-28865"},{"type":"FIX","url":"https://github.com/django-wiki/django-wiki/commit/8e280fd6c0bd27ce847c67b2d216c6cbf920f88c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/django-wiki/django-wiki","events":[{"introduced":"0"},{"fixed":"7981d6d88a33d3853ed68464f097423ce8d5d06a"}]}],"versions":["alpha/0.0.12","alpha/0.0.13","alpha/0.0.14","alpha/0.0.15","alpha/0.0.16","alpha/0.0.17","alpha/0.0.18","alpha/0.0.19","alpha/0.0.20","alpha/0.0.22","alpha/0.0.23","alpha/0.0.24","alpha/0.4a1","alpha/0.4a2","alpha/0.4a3","alpha/0.4a4","alpha/0.4a5","beta/0.3b1","beta/0.3b2","beta/0.3b3","beta/0.3b4","beta/0.4b1","beta/0.4b2","beta/0.4b3","beta/0.6b1","beta/0.6b2","releases/0.1","releases/0.1.1","releases/0.1.2","releases/0.2","releases/0.2.1","releases/0.2.2","releases/0.2.3","releases/0.2b1","releases/0.2b2","releases/0.3","releases/0.4","releases/0.4.1","releases/0.5","releases/0.6","releases/0.7","releases/0.7.1","releases/0.7.10","releases/0.7.2","releases/0.7.3","releases/0.7.4","releases/0.7.5","releases/0.7.6","releases/0.7.7","releases/0.7.8","releases/0.7.9","releases/0.8","releases/0.8.1","releases/0.8.2","releases/0.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-28865.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}