CVE-2026-84429

Source
https://cve.org/CVERecord?id=CVE-2026-84429
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84429.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-84429
Downstream
Published
2026-10-06T13:35:17Z
Modified
2026-10-08T02:52:10Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Potential denial-of-service vulnerability in HTTP header parsing
Details

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. django.utils.http.parse_header_parameters() was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with many separators inside a quoted parameter. An unauthenticated request could reach this parsing through headers such as Accept or Content-Type, for instance via the content negotiation performed by HttpRequest.accepts(). The per-call length limit does not bound the combined size of repeated headers. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Jisung Chae for reporting this issue.

Database specific
{
    "cna_assigner": "DSF",
    "cwe_ids": [
        "CWE-407"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84429.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "6.1"
                },
                {
                    "fixed": "6.1.2"
                },
                {
                    "introduced": "6.0"
                },
                {
                    "fixed": "6.0.9"
                },
                {
                    "introduced": "5.2"
                },
                {
                    "fixed": "5.2.18"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "6.1"
                },
                {
                    "fixed": "6.1.2"
                },
                {
                    "introduced": "6.0"
                },
                {
                    "fixed": "6.0.9"
                },
                {
                    "introduced": "5.2"
                },
                {
                    "fixed": "5.2.18"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/django/django

Affected ranges

Type
GIT
Repo
https://github.com/django/django
Events
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

1.*
1.0
1.1
1.2
1.2.1
1.3
1.4
1.7a2
5.*
5.2
5.2.1
5.2.10
5.2.11
5.2.12
5.2.13
5.2.14
5.2.15
5.2.16
5.2.17
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
5.2a1
5.2b1
5.2rc1
6.*
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0a1
6.0b1
6.0rc1
6.1
6.1.1
6.1a1
6.1b1
6.1rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84429.json"