GHSA-9v8h-57gv-qch6

Suggest an improvement
Source
https://github.com/advisories/GHSA-9v8h-57gv-qch6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9v8h-57gv-qch6/GHSA-9v8h-57gv-qch6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9v8h-57gv-qch6
Aliases
Published
2022-05-01T18:36:08Z
Modified
2024-11-18T16:26:20Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Django vulnerable to Denial of Service via i18n middleware component
Details

The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows remote attackers to cause a denial of service (memory consumption) via many HTTP requests with large Accept-Language headers.

Database specific
{
    "nvd_published_at": "2007-10-30T19:46:00Z",
    "cwe_ids": [
        "CWE-400"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2024-04-29T14:37:50Z"
}
References

Affected packages

PyPI / django

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.96.0
Fixed
0.96.1

Affected versions

0.*

0.96.0

PyPI / django

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.95
Fixed
0.95.2

PyPI / django

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.91.0
Fixed
0.91.1

Affected versions

0.*

0.91.0