CVE-2025-14550
HIGHDjango <6.0.2-4.2.28 - DoS
Title source: llmDescription
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote attacker to cause a potential denial-of-service via a crafted request with multiple duplicate headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Jiyong Yang for reporting this issue.
Scores
CVSS v3
7.5
EPSS
0.0006
EPSS Percentile
18.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-407
Status
published
Affected Products (2)
djangoproject/django
< 4.2.28
pypi/Django
< 6.0.2PyPI
Timeline
Published
Feb 03, 2026
Tracked Since
Feb 18, 2026