/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-rj3r-fgmx-r7pw

Published

Last updated

https://images.chainguard.dev/security/CGA-rj3r-fgmx-r7pw
Package

authentik

Repository

Chainguard

Latest Update
Not affected
Aliases
  • CVE-2025-64458
  • GHSA-qw25-v68c-qjf3

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-64458

Updates

Status

Not affected

Justification

Vulnerable code cannot be controlled by adversary

Impact

As per the security report this issue only affects code running on Windows. NFKC normalization in Python is slow on Windows. As a consequence, HttpResponseRedirect, HttpResponsePermanentRedirect, and redirect were subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters. More information can be found in the Django security release: https://www.djangoproject.com/weblog/2025/nov/05/security-releases/


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing