Django issued security releases 5.2.9, 5.1.15, and 4.2.27 to fix CVE-2025-64460, a denial-of-service vulnerability in the framework's XML deserialization logic. The flaw is rooted in django.core.serializers.xml_serializer.getInnerText(), where specially crafted XML can trigger excessive CPU and memory consumption, allowing a remote attacker to exhaust resources and disrupt affected applications. The issue was reported by Seokchan Yoon and affects supported Django branches before those patched versions; unsupported branches including 5.0.x, 4.1.x, and 3.2.x were not evaluated and may also be exposed.
Red Hat classified the bug as Important with a CVSS v3.1 score of 7.5 and said no acceptable mitigation was available at publication, making patching the primary response. The company warned that products using Django's XML Deserializer may be affected, including Red Hat Ansible Automation Platform, Red Hat OpenStack Platform, and OpenShift Service Mesh, and published fixes for multiple Ansible Automation Platform releases through advisories RHSA-2026:1249, RHSA-2026:1497, and RHSA-2026:1506.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat marked Red Hat Ansible Automation Platform 2.6 for RHEL 9 packages, including automation-controller and python3.11-django, as fixed for CVE-2025-64460 in advisory RHSA-2026:1249.
Red Hat last modified its CVE-2025-64460 entry, updating the vendor tracking information for the Django denial-of-service issue. The record continued to note that no acceptable mitigation was available at that time.
Red Hat published its CVE record for CVE-2025-64460, describing the Django XML Deserializer denial-of-service flaw and identifying affected Red Hat product families. The entry rated the issue Important and assigned a CVSS v3.1 score of 7.5.
Django issued security releases 5.2.9, 5.1.15, and 4.2.27 to address an algorithmic complexity flaw in the XML Deserializer that can lead to denial of service via CPU and memory exhaustion. Django credited Seokchan Yoon with reporting the issue.
Red Hat marked Red Hat Ansible Automation Platform 2.5 lightspeed-rhel8 as fixed for CVE-2025-64460 in advisory RHSA-2026:1609.
Red Hat marked Red Hat Ansible Automation Platform 2.4 lightspeed-rhel8 as fixed for CVE-2025-64460 in advisory RHSA-2026:1599.
Red Hat marked Red Hat Ansible Automation Platform 2.4 for RHEL 8 and RHEL 9 as fixed in RHSA-2026:1497, and AAP 2.5 for RHEL 8 and RHEL 9 as fixed in RHSA-2026:1506 for CVE-2025-64460.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourcedjangoproject.com
Open sourcegroups.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.