PT-2026-30851 · Djangoproject · Django
Jacob Walls
+2
·
Published
2026-04-07
·
Updated
2026-04-07
·
CVE-2026-33034
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.
ASGI requests with a missing or understated
Content-Length header could
bypass the DATA UPLOAD MAX MEMORY SIZE limit when reading
HttpRequest.body, allowing remote attackers to load an unbounded request body into
memory.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Superior for reporting this issue.Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Django