Denial-of-Service Vulnerability in Django Web Framework
CVE-2026-84429
What is CVE-2026-84429?
A denial-of-service vulnerability has been identified in the Django web framework affecting versions 6.1 prior to 6.1.2, 6.0 prior to 6.0.9, and 5.2 prior to 5.2.18. The issue stems from the django.utils.http.parse_header_parameters() function, which exhibits quadratic time complexity when processing values containing multiple separators within quoted parameters. This design flaw allows an unauthenticated attacker to exploit request headers, such as 'Accept' or 'Content-Type', potentially leading to service disruption. Past unsupported versions, including 5.1.x, 5.0.x, and 4.2.x, may also harbor similar vulnerabilities, as they were not thoroughly evaluated. Django acknowledges Jisung Chae for reporting this concern, and users are urged to upgrade to the latest versions to mitigate risks.
Affected Version(s)
Django 6.1 < 6.1.2
Django 6.0 < 6.0.9
Django 5.2 < 5.2.18
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
