An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote attacker to cause a potential denial-of-service via a crafted request with multiple duplicate headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Jiyong Yang for reporting this issue.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-django | Feb 10, 2026 | Feb 3, 2026 |
| Debian | — | Upgrade python-django | Mar 2, 2026 | Mar 2, 2026 |
| Redhat_linux | — | Upgrade ansible-coreUpgrade python3.12-pysequoia-debuginfoUpgrade receptorctlUpgrade automation-gatewayUpgrade python3.12-django-ansible-base+activitystreamUpgrade ansible-testUpgrade python3-blackUpgrade python3.12-pysequoia-debugsourceUpgrade python3.12-pulp-containerUpgrade python3.12-pyjwtUpgrade python3.12-galaxy-ngUpgrade python3.12-pyjwt+cryptoUpgrade python3.12-pyOpenSSLUpgrade automation-controller-uiUpgrade receptor-debugsourceUpgrade python3-pathspecUpgrade python3.12-galaxy-importerUpgrade python3-pytokens-debuginfoUpgrade python3.12-pytokens-debuginfoUpgrade python3-wheel-wheelUpgrade python3.12-cffiUpgrade python3.12-pulpcoreUpgrade python3.12-django-ansible-base+oauth2_providerUpgrade python3.12-django-ansible-base+authenticationUpgrade python3.12-cffi-debugsourceUpgrade python3.12-dynaconfUpgrade automation-hubUpgrade automation-eda-controller-baseUpgrade python3.12-pyasn1-modulesUpgrade python3.12-cryptographyUpgrade automation-gateway-serverUpgrade python3.12-pysequoiaUpgrade automation-eda-controller-worker-servicesUpgrade python3.12-jwcryptoUpgrade python3.12-django-ansible-base+redis_clientUpgrade python3.12-django-ansible-baseUpgrade python3.12-pyasn1Upgrade python3.12-cryptography-debuginfoUpgrade python3.12-django-ansible-base+rbacUpgrade automation-eda-controllerUpgrade automation-gateway-proxyUpgrade python3.12-blackUpgrade yamllintUpgrade python3.12-pathspecUpgrade automation-eda-controller-base-servicesUpgrade ansible-lintUpgrade automation-controller-venv-towerUpgrade python3.12-cffi-debuginfoUpgrade python3.12-django-ansible-base+channel_authUpgrade python3.12-django-ansible-base+resource_registryUpgrade python3.12-cryptography-debugsourceUpgrade receptor-debuginfoUpgrade python3.12-django-ansible-base+api_documentationUpgrade automation-eda-controller-event-stream-servicesUpgrade automation-platform-uiUpgrade python3.12-pytokensUpgrade python3.12-markdownUpgrade automation-gateway-configUpgrade python3.12-django-ansible-base+jwt_consumerUpgrade python3-pytokensUpgrade receptorUpgrade automation-gateway-proxy-debugsourceUpgrade automation-gateway-proxy-server-debuginfoUpgrade python3.12-pytokens-debugsourceUpgrade automation-gateway-proxy-serverUpgrade automation-controller-cliUpgrade python3.12-django-ansible-base+rest_filtersUpgrade python3.12-django-ansible-base+feature_flagsUpgrade automation-controller-serverUpgrade python-pytokens-debugsourceUpgrade automation-controller | May 6, 2026 | Feb 3, 2026 |
| Ubuntu | — | Upgrade python-django (Ubuntu Pro)Upgrade python3-django (Ubuntu Pro)Upgrade python3-django | Feb 4, 2026 | Feb 3, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub