CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-84429: Django 6.1 to before 6.1.2, 6.0 to before 6.0.9, 5.2 to before 5.2.18

CVE-2026-84429. CVSS 3.1 base score 5.3 (MEDIUM, Source advisory).

Affected technology

Django · 6.1 to before 6.1.2, 6.0 to before 6.0.9, 5.2 to before 5.2.18
djangoproject

Description’s affected range: before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.http.parse_header_parameters()` was subject to a potential denial-of-service attack due to quadratic

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could disrupt service under the conditions described by the source. Source advisory’s CVSS 4.0 assessment (base score 6.9/10) rates confidentiality and integrity impact as none; availability impact as low.

Published

CWE
CWE-407
CCR priority
21.2 /100 (P4)
CVSS 3.1
5.3 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L · Source advisory
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-84429.html