{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-84429","assignerOrgId":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92","state":"PUBLISHED","assignerShortName":"DSF","dateReserved":"2026-09-01T18:34:27.131Z","datePublished":"2026-10-06T13:35:17.443Z","dateUpdated":"2026-10-06T14:15:10.916Z"},"containers":{"cna":{"providerMetadata":{"orgId":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92","shortName":"DSF","dateUpdated":"2026-10-06T13:35:17.443Z"},"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-407","description":"CWE-407: Inefficient Algorithmic Complexity","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-130","descriptions":[{"lang":"en","value":"CAPEC-130: Excessive Allocation"}]}],"title":"Potential denial-of-service vulnerability in HTTP header parsing","metrics":[{"other":{"content":{"value":"moderate","namespace":"https://docs.djangoproject.com/en/dev/internals/security/#security-issue-severity-levels"},"type":"Django severity rating"}},{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM"}},{"cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","baseScore":6.9,"baseSeverity":"MEDIUM"}}],"descriptions":[{"lang":"en","value":"An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18.\n`django.utils.http.parse_header_parameters()` was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with many separators inside a quoted parameter. An unauthenticated request could reach this parsing through headers such as `Accept` or `Content-Type`, for instance via the content negotiation performed by `HttpRequest.accepts()`. The per-call length limit does not bound the combined size of repeated headers.\nEarlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.\nDjango would like to thank Jisung Chae for reporting this issue.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18.</p><p><code>django.utils.http.parse_header_parameters()</code> was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with many separators inside a quoted parameter. An unauthenticated request could reach this parsing through headers such as <code>Accept</code> or <code>Content-Type</code>, for instance via the content negotiation performed by <code>HttpRequest.accepts()</code>. The per-call length limit does not bound the combined size of repeated headers.</p><p>Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.</p><p>Django would like to thank Jisung Chae for reporting this issue.</p>"}]}],"affected":[{"collectionURL":"https://pypi.org/project/Django/","defaultStatus":"unaffected","packageName":"django","product":"Django","repo":"https://github.com/django/django/","vendor":"djangoproject","versions":[{"status":"affected","version":"6.1","lessThan":"6.1.2","versionType":"python"},{"status":"unaffected","version":"6.1.2","versionType":"python"},{"status":"affected","version":"6.0","lessThan":"6.0.9","versionType":"python"},{"status":"unaffected","version":"6.0.9","versionType":"python"},{"status":"affected","version":"5.2","lessThan":"5.2.18","versionType":"python"},{"status":"unaffected","version":"5.2.18","versionType":"python"}]}],"references":[{"url":"https://docs.djangoproject.com/en/dev/releases/security/","name":"Django security archive","tags":["vendor-advisory"]},{"url":"https://groups.google.com/g/django-announce","name":"Django releases announcements","tags":["mailing-list"]},{"tags":["patch"],"url":"https://github.com/django/django/commit/7ff7fcc0508864a4bc39693128ace38b1e95a890"},{"tags":["patch"],"url":"https://github.com/django/django/commit/de56deeabd4c48dfb5193f0001469d80102fb367"},{"tags":["patch"],"url":"https://github.com/django/django/commit/3d8f121695c21234aff3071de0d38b6bd38c3f52"},{"tags":["patch"],"url":"https://github.com/django/django/commit/6ecd66e09a383be004a78a3a738ea9727ff07b0e"},{"url":"https://www.djangoproject.com/weblog/2026/oct/06/security-releases/","name":"Django security releases issued: 6.1.2, 6.0.9, and 5.2.18","tags":["vendor-advisory"]}],"credits":[{"lang":"en","type":"reporter","value":"Jisung Chae"},{"lang":"en","type":"analyst","value":"Peter Thomassen"},{"lang":"en","type":"analyst","value":"Bruno Alla"},{"lang":"en","type":"analyst","value":"Natalia Bidart"},{"lang":"en","type":"remediation developer","value":"Natalia Bidart"},{"lang":"en","type":"remediation developer","value":"Khudyakov Artem"},{"lang":"en","type":"remediation developer","value":"Ben Cail"},{"lang":"en","type":"remediation reviewer","value":"Jake Howard"},{"lang":"en","type":"remediation reviewer","value":"Sarah Boyce"},{"lang":"en","type":"remediation reviewer","value":"Jacob Walls"},{"lang":"en","type":"remediation reviewer","value":"Mike Edmunds"},{"lang":"en","type":"remediation reviewer","value":"David Smith"},{"lang":"en","type":"coordinator","value":"Sarah Boyce"}],"timeline":[{"lang":"en","time":"2026-08-26T00:00:00.000Z","value":"Initial report received."},{"lang":"en","time":"2026-09-01T00:00:00.000Z","value":"Vulnerability confirmed."},{"lang":"en","time":"2026-10-06T08:00:00.000Z","value":"Security release issued."}],"datePublic":"2026-10-06T08:00:00.000Z","source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-10-06T14:12:40.577982Z","id":"CVE-2026-84429","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-10-06T14:15:10.916Z"}}]}}