Denial-of-Service Vulnerability in Django Web Framework
CVE-2026-84429

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-84429?

A denial-of-service vulnerability has been identified in the Django web framework affecting versions 6.1 prior to 6.1.2, 6.0 prior to 6.0.9, and 5.2 prior to 5.2.18. The issue stems from the django.utils.http.parse_header_parameters() function, which exhibits quadratic time complexity when processing values containing multiple separators within quoted parameters. This design flaw allows an unauthenticated attacker to exploit request headers, such as 'Accept' or 'Content-Type', potentially leading to service disruption. Past unsupported versions, including 5.1.x, 5.0.x, and 4.2.x, may also harbor similar vulnerabilities, as they were not thoroughly evaluated. Django acknowledges Jisung Chae for reporting this concern, and users are urged to upgrade to the latest versions to mitigate risks.

Affected Version(s)

Django 6.1 < 6.1.2

Django 6.0 < 6.0.9

Django 5.2 < 5.2.18

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jisung Chae
Peter Thomassen
Bruno Alla
Natalia Bidart
Natalia Bidart
Khudyakov Artem
Ben Cail
Jake Howard
Sarah Boyce
Jacob Walls
Mike Edmunds
David Smith
Sarah Boyce
.