Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-07725

Опубликовано: 07 апр. 2026
Источник: fstec
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

Уязвимость механизма обработки ASGI-запросов программной платформы для веб-приложений Django связана с неограниченным распределением ресурсов. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, вызвать отказ в обслуживании

Вендор

ООО «Ред Софт»
Canonical Ltd.
Django Software Foundation

Наименование ПО

РЕД ОС
Ubuntu
Django

Версия ПО

7.3 (РЕД ОС)
24.04 LTS (Ubuntu)
25.10 (Ubuntu)
8.0 (РЕД ОС)
от 4.2 до 4.2.30 (Django)
от 5.2 до 5.2.13 (Django)
от 6.0 до 6.0.4 (Django)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 7.3
Canonical Ltd. Ubuntu 24.04 LTS
Canonical Ltd. Ubuntu 25.10
ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,8)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7,5)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для Django:
https://www.djangoproject.com/weblog/2026/apr/07/security-releases/
https://github.com/django/django/commit/953c238058c0ce387a1a41cb491bfc1875d73ad0
https://github.com/django/django/commit/393dbc53e848876fdba92fbf02e10ee6a6eace6b
https://github.com/django/django/commit/49e1e2b548999a35a025f9682598946bda9e9921
https://github.com/django/django/commit/ed4dfda62718a0bb644b80ac8b1d3099861f2295
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=&q=CVE-2026-33034
Для Ubuntu:
https://ubuntu.com/security/CVE-2026-33034

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 51%
0.00769
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Связанные уязвимости

CVSS3: 7.5
redos
3 месяца назад

Уязвимость python-django

CVSS3: 7.5
ubuntu
4 месяца назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.

CVSS3: 5.3
redhat
4 месяца назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.

CVSS3: 7.5
nvd
4 месяца назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.

CVSS3: 7.5
debian
4 месяца назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4. ...

EPSS

Процентиль: 51%
0.00769
Низкий

7.5 High

CVSS3

7.8 High

CVSS2