summaryrefslogtreecommitdiff
path: root/docs/releases/4.2.3.txt
diff options
context:
space:
mode:
Diffstat (limited to 'docs/releases/4.2.3.txt')
-rw-r--r--docs/releases/4.2.3.txt7
1 files changed, 7 insertions, 0 deletions
diff --git a/docs/releases/4.2.3.txt b/docs/releases/4.2.3.txt
index 835de58116..c105849739 100644
--- a/docs/releases/4.2.3.txt
+++ b/docs/releases/4.2.3.txt
@@ -7,6 +7,13 @@ Django 4.2.3 release notes
Django 4.2.3 fixes a security issue with severity "moderate" and several bugs
in 4.2.2.
+CVE-2023-36053: Potential regular expression denial of service vulnerability in ``EmailValidator``/``URLValidator``
+===================================================================================================================
+
+``EmailValidator`` and ``URLValidator`` were subject to potential regular
+expression denial of service attack via a very large number of domain name
+labels of emails and URLs.
+
Bugfixes
========