Junglewise Threat Intelligence

CVE-2026-3902: Django ASGI header spoofing via underscore/hyphen conflation

CVE-2026-3902 · Severity: high · CVSS 7.5 · Published 2026-04-07

Technologies: Django Software Foundation Django, Django (PyPI). Vendors: Django Software Foundation, PyPI.

Executive brief

A vulnerability in the Django web framework could allow remote attackers to bypass security checks by spoofing web request headers. This occurs because the system incorrectly treats hyphens and underscores as identical when processing certain types of web requests (ASGI). An attacker could use this to impersonate other users or bypass authentication mechanisms, potentially leading to unauthorized access to sensitive data or administrative functions.

Technical details

A vulnerability exists in Django's ASGIRequest class where it incorrectly maps HTTP headers containing hyphens and underscores to the same internal representation. Specifically, the mapping process conflates these two characters, allowing a remote attacker to provide a malicious header that is interpreted as a different, security-critical header. This is classified as CWE-290 (Authentication Bypass by Spoofing). The attack can be carried out over the network without authentication or user interaction. Patches are available in versions 6.0.4, 5.2.13, and 4.2.30.

Affected products

  • Django Software Foundation Django >= 6.0, < 6.0.4
  • Django Software Foundation Django >= 5.2, < 5.2.13
  • Django Software Foundation Django >= 4.2, < 4.2.30

Timeline

  • 2026-04-07: disclosed
  • 2026-04-07: advisory
  • 2026-04-07: patched

References

Related threats