Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mvfq-ggxm-9mc5

Опубликовано: 07 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Django vulnerable to ASGI header spoofing via underscore/hyphen conflation

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGIRequest allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores.

Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 6.0, < 6.0.4

6.0.4

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 5.2, < 5.2.13

5.2.13

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 4.2, < 4.2.30

4.2.30

EPSS

Процентиль: 14%
0.00047
Низкий

7.5 High

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 дней назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 5.3
redhat
8 дней назад

A flaw was found in Django. A remote attacker can exploit an ambiguous mapping of header variants (with hyphens or underscores) to a single version with underscores in `ASGIRequest`. This vulnerability allows the attacker to spoof headers, potentially leading to unauthorized actions or misdirection within the application.

CVSS3: 7.5
nvd
8 дней назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS3: 7.5
debian
8 дней назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4. ...

EPSS

Процентиль: 14%
0.00047
Низкий

7.5 High

CVSS3

Дефекты

CWE-290