Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-84429— Potential denial-of-service vulnerability in HTTP header parsing

Quick assessment

Affected
djangoproject Django
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Django 6.1(6.1.2 之前版本)、6.0(6.0.9 之前版本)以及 5.2(5.2.18 之前版本)中发现一个问题。 函数 在处理带引号参数中包含大量分隔符的值时,由于存在二次时间复杂度(quadratic time complexity),可能遭受拒绝服务(DoS)攻击。未经身份验证的请求可以通过诸如 或 等 HTTP 头部访问此解析逻辑,例如通过 方法执行的内容协商。尽管存在每次调用的长度限制,但该限制并未约束重复出现的头部字段的总大小。 此前,Django 官方不再支持的系列版本(如 5.1

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84429

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Potential denial-of-service vulnerability in HTTP header parsing
Source: CVE Program / CVE List V5
Vulnerability Description
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.http.parse_header_parameters()` was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with many separators inside a quoted parameter. An unauthenticated request could reach this parsing through headers such as `Accept` or `Content-Type`, for instance via the content negotiation performed by `HttpRequest.accepts()`. The per-call length limit does not bound the combined size of repeated headers. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Jisung Chae for reporting this issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
算法复杂性
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
djangoproject Django 6.1 ~ 6.1.2 -

II. Public POCs for CVE-2026-84429

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84429

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-84429 (1)

Mailing List Discussions for CVE-2026-84429 (1)

Other References for CVE-2026-84429 (5)

Same Patch Batch · djangoproject · 2026-10-06 · 4 CVEs total

CVE-2026-87890 5.3 MEDIUM Potential request forgery via spatial lookup byte values
CVE-2026-77050 5.3 MEDIUM Potential denial-of-service vulnerability in get_supported_language_variant()
CVE-2026-87975 4.3 MEDIUM Privilege abuse in model formsets with editable primary keys

IV. Related Vulnerabilities

V. Comments for CVE-2026-84429

No comments yet


Leave a comment