Executive brief
A vulnerability in the Django web framework could allow an attacker to crash a server by sending specially crafted web requests. By omitting or misstating the size of an uploaded file, an attacker can bypass security limits and force the server to load an unlimited amount of data into its memory. This can lead to a denial-of-service condition, making the website or application unavailable to legitimate users.
Technical details
A resource exhaustion vulnerability exists in Django's handling of ASGI requests. When reading 'HttpRequest.body', the framework fails to properly enforce the 'DATA_UPLOAD_MAX_MEMORY_SIZE' limit if the 'Content-Length' header is missing or provides an understated value. A remote, unauthenticated attacker can exploit this by sending a large request body, causing the server to allocate unbounded memory. This leads to a Denial of Service (DoS) via memory exhaustion. The issue is fixed in Django versions 6.0.4, 5.2.13, and 4.2.30.
Affected products
- Django Software Foundation Django >= 6.0, < 6.0.4; >= 5.2, < 5.2.13; >= 4.2, < 4.2.30
Timeline
- 2026-04-07: disclosed
- 2026-04-07: advisory
- 2026-04-07: patched