Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-33034

Опубликовано: 07 апр. 2026
Источник: ubuntu
Приоритет: low
CVSS3: 7.5

Описание

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated Content-Length header could bypass the DATA_UPLOAD_MAX_MEMORY_SIZE limit when reading HttpRequest.body, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.

РелизСтатусПримечание
devel

released

3:5.2.9-0ubuntu4
esm-infra-legacy/trusty

ignored

see notes
esm-infra-legacy/xenial

ignored

see notes
esm-infra/bionic

ignored

see notes
esm-infra/focal

ignored

see notes
esm-infra/xenial

ignored

end of ESM support, was ignored [see notes]
jammy

ignored

see notes
noble

released

3:4.2.11-1ubuntu1.15
questing

released

3:5.2.4-1ubuntu2.4
upstream

released

5.2.13,4.2.30

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
5 месяцев назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.

CVSS3: 7.5
nvd
5 месяцев назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.

CVSS3: 7.5
debian
5 месяцев назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4. ...

CVSS3: 7.5
redos
4 месяца назад

Уязвимость python-django

CVSS3: 7.5
github
5 месяцев назад

Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit

7.5 High

CVSS3