Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-09775

Опубликовано: 05 мая 2026
Источник: fstec
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Уязвимость программной платформы для веб-приложений Django связана с неправильной обработкой несоответствия параметра длины. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, вызвать отказ в обслуживании

Вендор

ООО «Ред Софт»
Red Hat Inc.
Canonical Ltd.
Django Software Foundation

Наименование ПО

РЕД ОС
Red Hat Satellite
Ubuntu
Red Hat OpenStack Platform
Red Hat Update Infrastructure for Cloud Providers
Red Hat Ansible Automation Platform
Discovery
Django

Версия ПО

7.3 (РЕД ОС)
6 (Red Hat Satellite)
22.04 LTS (Ubuntu)
16.2 (Red Hat OpenStack Platform)
4 (Red Hat Update Infrastructure for Cloud Providers)
2 (Red Hat Ansible Automation Platform)
17.1 (Red Hat OpenStack Platform)
24.04 LTS (Ubuntu)
18.0 (Red Hat OpenStack Platform)
8.0 (РЕД ОС)
2 (Discovery)
26.04 LTS (Ubuntu)
до 6.0.5 (Django)
до 5.2.14 (Django)

Тип ПО

Операционная система
Прикладное ПО информационных систем
ПО программно-аппаратного средства
Сетевое программное средство

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 7.3
Canonical Ltd. Ubuntu 22.04 LTS
Canonical Ltd. Ubuntu 24.04 LTS
ООО «Ред Софт» РЕД ОС 8.0
Canonical Ltd. Ubuntu 26.04 LTS

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 5)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 5,3)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для Django:
https://www.djangoproject.com/weblog/2026/may/05/security-releases/
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2026-5766
Для Ubuntu:
https://ubuntu.com/security/CVE-2026-5766
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-5766

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 35%
0.00423
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.3
redos
около 1 месяца назад

Уязвимость python-django

CVSS3: 5.3
ubuntu
3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and causing service degradation. As a reminder, Django expects a limit to be configured at the web server level rather than solely relying on `FILE_UPLOAD_MAX_MEMORY_SIZE`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Kyle Agronick for reporting this issue.

CVSS3: 5.3
redhat
3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and causing service degradation. As a reminder, Django expects a limit to be configured at the web server level rather than solely relying on `FILE_UPLOAD_MAX_MEMORY_SIZE`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Kyle Agronick for reporting this issue.

CVSS3: 5.3
nvd
3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and causing service degradation. As a reminder, Django expects a limit to be configured at the web server level rather than solely relying on `FILE_UPLOAD_MAX_MEMORY_SIZE`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Kyle Agronick for reporting this issue.

CVSS3: 5.3
debian
3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASG ...

EPSS

Процентиль: 35%
0.00423
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2