CVE-2026-84429
Deferred Deferred - Pending Action

Denial-of-Service in Django via Header Parsing

Vulnerability report for CVE-2026-84429, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: Django Software Foundation

Description

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.http.parse_header_parameters()` was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with many separators inside a quoted parameter. An unauthenticated request could reach this parsing through headers such as `Accept` or `Content-Type`, for instance via the content negotiation performed by `HttpRequest.accepts()`. The per-call length limit does not bound the combined size of repeated headers. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Jisung Chae for reporting this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
djangoproject Django 6.1
djangoproject Django 6.0
djangoproject Django 5.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-407 An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial-of-service issue in Django versions before 6.1.2, 6.0.9, and 5.2.18. It occurs in the function django.utils.http.parse_header_parameters() due to quadratic time complexity when parsing values with many separators inside quoted parameters. Attackers can exploit this by sending crafted headers like Accept or Content-Type, potentially causing excessive server load.

Detection Guidance

Detecting this vulnerability requires checking the installed Django version. Run: python -c "import django; print(django.get_version())" to verify if your version is below 6.1.2, 6.0.9, or 5.2.18. If using an unsupported series like 5.1.x, 5.0.x, or 4.2.x, it may also be affected.

Impact Analysis

An unauthenticated attacker could send malicious requests to a vulnerable Django server, causing it to consume excessive CPU resources and potentially crash or slow down the service. This could disrupt normal operations for users and services relying on the affected Django application.

Mitigation Strategies

Upgrade Django to a patched version: 6.1.2, 6.0.9, or 5.2.18. If using an unsupported series, upgrade to a supported version immediately. Monitor incoming requests with headers like Accept or Content-Type for unusual patterns indicating potential DoS attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84429. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart