Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-33034

Опубликовано: 07 апр. 2026
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 7.5

Описание

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated Content-Length header could bypass the DATA_UPLOAD_MAX_MEMORY_SIZE limit when reading HttpRequest.body, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.

РелизСтатусПримечание
devel

released

3:5.2.9-0ubuntu4
esm-infra-legacy/trusty

ignored

see notes
esm-infra-legacy/xenial

ignored

see notes
esm-infra/bionic

ignored

see notes
esm-infra/focal

ignored

see notes
esm-infra/xenial

ignored

end of ESM support, was ignored [see notes]
jammy

ignored

see notes
noble

released

3:4.2.11-1ubuntu1.15
questing

released

3:5.2.4-1ubuntu2.4
upstream

released

5.2.13,4.2.30

Показывать по

EPSS

Процентиль: 51%
0.00769
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
4 месяца назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.

CVSS3: 7.5
nvd
4 месяца назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.

CVSS3: 7.5
debian
4 месяца назад

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4. ...

CVSS3: 7.5
github
4 месяца назад

Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость механизма обработки ASGI-запросов программной платформы для веб-приложений Django, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 51%
0.00769
Низкий

7.5 High

CVSS3