diff options
| author | Mariusz Felisiak <felisiak.mariusz@gmail.com> | 2023-06-14 12:23:06 +0200 |
|---|---|---|
| committer | Mariusz Felisiak <felisiak.mariusz@gmail.com> | 2023-07-03 08:16:55 +0200 |
| commit | ad0410ec4f458aa39803e5f6b9a3736527062dcd (patch) | |
| tree | 8478f3d54b37cb481124e3f60acf3b531a12cb63 /django/forms | |
| parent | 7eeadc82c2f7d7a778e3bb43c34d642e6275dacf (diff) | |
Fixed CVE-2023-36053 -- Prevented potential ReDoS in EmailValidator and URLValidator.
Thanks Seokchan Yoon for reports.
Diffstat (limited to 'django/forms')
| -rw-r--r-- | django/forms/fields.py | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/django/forms/fields.py b/django/forms/fields.py index b8316079a3..bd226de543 100644 --- a/django/forms/fields.py +++ b/django/forms/fields.py @@ -616,6 +616,9 @@ class EmailField(CharField): default_validators = [validators.validate_email] def __init__(self, **kwargs): + # The default maximum length of an email is 320 characters per RFC 3696 + # section 3. + kwargs.setdefault("max_length", 320) super().__init__(strip=True, **kwargs) |
