Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33034

Опубликовано: 07 апр. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated Content-Length header could bypass the DATA_UPLOAD_MAX_MEMORY_SIZE limit when reading HttpRequest.body, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.

A flaw was found in Django. A remote attacker can exploit this vulnerability by sending ASGI (Asynchronous Server Gateway Interface) requests with a missing or understated Content-Length header. This allows the attacker to bypass the DATA_UPLOAD_MAX_MEMORY_SIZE limit, leading to an unbounded request body being loaded into memory. This can result in a Denial of Service (DoS) condition, making the application unavailable to legitimate users.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8-operatorFix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-rhel9-operatorFix deferred
Red Hat Ansible Automation Platform 2automation-controllerFix deferred
Red Hat Ansible Automation Platform 2redhat-user-workloads/automation-reportsFix deferred
Red Hat Ansible Automation Platform 2redhat-user-workloads/controller-rhel9Fix deferred
Red Hat Ansible Automation Platform 2redhat-user-workloads/eda-controller-rhel9Fix deferred
Red Hat Ansible Automation Platform 2redhat-user-workloads/gateway-rhel9Fix deferred
Red Hat Ansible Automation Platform 2redhat-user-workloads/hub-rhel9Fix deferred
Red Hat Ansible Automation Platform 2redhat-user-workloads/metrics-service-rhel9Fix deferred
Red Hat Discovery 2redhat-user-workloads/discovery-serverFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-130
https://bugzilla.redhat.com/show_bug.cgi?id=2455927Django: Django: Denial of Service via missing or understated Content-Length header in ASGI requests

EPSS

Процентиль: 52%
0.00769
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.

CVSS3: 7.5
nvd
4 месяца назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.

CVSS3: 7.5
debian
4 месяца назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4. ...

CVSS3: 7.5
github
4 месяца назад

Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость механизма обработки ASGI-запросов программной платформы для веб-приложений Django, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 52%
0.00769
Низкий

5.3 Medium

CVSS3