在 Django 6.1 早期版本至 6.1.2、6.0 早期版本至 6.0.9 以及 5.2 早期版本至 5.2.18 中,发现了一个安全问题。 函数在处理大量不同的、非常长的语言代码时,存在潜在的拒绝服务(DoS)攻击风险。这些语言代码会被作为键保留在内存缓存中,从而消耗大量的进程内存。 此前,不支持的 Django 系列版本(例如 5.1.x、5.0.x 和 4.2.x)未经过安全评估,但也可能受到影响。 Django 项目组感谢 Gleb Lizunov 报告了此安全问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| djangoproject | Django | 6.1 ~ 6.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87890 | 5.3 MEDIUM | Potential request forgery via spatial lookup byte values |
| CVE-2026-84429 | 5.3 MEDIUM | Potential denial-of-service vulnerability in HTTP header parsing |
| CVE-2026-87975 | 4.3 MEDIUM | Privilege abuse in model formsets with editable primary keys |
No comments yet