在 Django 6.1(6.1.2 之前版本)、6.0(6.0.9 之前版本)以及 5.2(5.2.18 之前版本)中发现一个问题。 函数 在处理带引号参数中包含大量分隔符的值时,由于存在二次时间复杂度(quadratic time complexity),可能遭受拒绝服务(DoS)攻击。未经身份验证的请求可以通过诸如 或 等 HTTP 头部访问此解析逻辑,例如通过 方法执行的内容协商。尽管存在每次调用的长度限制,但该限制并未约束重复出现的头部字段的总大小。 此前,Django 官方不再支持的系列版本(如 5.1
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| djangoproject | Django | 6.1 ~ 6.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87890 | 5.3 MEDIUM | Potential request forgery via spatial lookup byte values |
| CVE-2026-77050 | 5.3 MEDIUM | Potential denial-of-service vulnerability in get_supported_language_variant() |
| CVE-2026-87975 | 4.3 MEDIUM | Privilege abuse in model formsets with editable primary keys |
No comments yet