PT-2026-30850 · Django+3 · Django+3
Jacob Walls
+2
·
Published
2026-04-07
·
Updated
2026-05-24
·
CVE-2026-33033
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Django versions 4.2 through 4.2.29, 5.2 through 5.2.12, and 6.0 through 6.0.3
Description
The
MultiPartParser component is susceptible to performance degradation when processing multipart uploads containing Content-Transfer-Encoding: base64 with excessive whitespace. Remote attackers can exploit this to negatively impact system performance.Recommendations
Update to Django version 6.0.4 or later.
Update to Django version 5.2.13 or later.
Update to Django version 4.2.30 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Django
Linuxmint
Red Os
Ubuntu