Django security releases issued: 3.0.1, 2.2.9, and 1.11.27
djangoproject.com
djangoproject.com
https://news.ycombinator.com/item?id=21809390
https://eng.getwisdom.io/hacking-github-with-unicode-dotless...
It makes you wander how wide spread this vulnerability could be with two independent implementations found so far. I’m guessing this was found when someone audited the Django email comparison code after reading about the GutHub one.
Everyone who maintains a password reset form should be auditing for the same issue ASAP.
Naturally, the top-rated comment in the thread you linked makes a much better point than I ever could!