An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
`ASGIRequest` allows a remote attacker to cause a potential denial-of-service via a crafted request with multiple duplicate headers.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Jiyong Yang for reporting this issue.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote attacker to cause a potential denial-of-service via a crafted request with multiple duplicate headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Jiyong Yang for reporting this issue. | |
| Title | Potential denial-of-service vulnerability via repeated headers when using ASGI | |
| Weaknesses | CWE-407 | |
| References |
|
Status: PUBLISHED
Assigner: DSF
Published:
Updated: 2026-02-03T16:27:38.976Z
Reserved: 2025-12-11T20:08:21.400Z
Link: CVE-2025-14550
No data.
Status : Awaiting Analysis
Published: 2026-02-03T15:16:11.750
Modified: 2026-02-03T16:44:03.343
Link: CVE-2025-14550
No data.
OpenCVE Enrichment
No data.