CVE-2026-25673 | Django up to 4.2.28/5.2.11/6.0.2 on Windows NFKC Normalization urllib.parse.urlsplit resource consumption
A vulnerability has been found in Django up to 4.2.28/5.2.11/6.0.2 on Windows and classified as problematic. Affected by this issue is the function urllib.parse.urlsplit of the component NFKC Normalization. This manipulation causes resource consumption.
This vulnerability is tracked as CVE-2026-25673. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.