CVE-2026-84429 PUBLISHED

Potential denial-of-service vulnerability in HTTP header parsing

Assigner: DSF
Reserved: 01.09.2026 Published: 06.10.2026 Updated: 06.10.2026

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. django.utils.http.parse_header_parameters() was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with many separators inside a quoted parameter. An unauthenticated request could reach this parsing through headers such as Accept or Content-Type, for instance via the content negotiation performed by HttpRequest.accepts(). The per-call length limit does not bound the combined size of repeated headers. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Jisung Chae for reporting this issue.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor djangoproject
Product Django
Versions Default: unaffected
  • affected from 6.1 to 6.1.2 (excl.)
  • Version 6.1.2 is unaffected
  • affected from 6.0 to 6.0.9 (excl.)
  • Version 6.0.9 is unaffected
  • affected from 5.2 to 5.2.18 (excl.)
  • Version 5.2.18 is unaffected

Credits

  • Jisung Chae reporter
  • Peter Thomassen analyst
  • Bruno Alla analyst
  • Natalia Bidart analyst
  • Natalia Bidart remediation developer
  • Khudyakov Artem remediation developer
  • Ben Cail remediation developer
  • Jake Howard remediation reviewer
  • Sarah Boyce remediation reviewer
  • Jacob Walls remediation reviewer
  • Mike Edmunds remediation reviewer
  • David Smith remediation reviewer
  • Sarah Boyce coordinator

References

Problem Types

  • CWE-407: Inefficient Algorithmic Complexity CWE

Impacts

  • CAPEC-130: Excessive Allocation