Inefficient Algorithmic Complexity in Django - CVE-2026-84429
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
nThe vulnerability exists due to quadratic time complexity in django.utils.http.parse_header_parameters() when parsing header values containing many separators inside a quoted parameter. A remote attacker can send a specially crafted request containing such values in Accept or Content-Type headers to cause a denial of service.
nUnauthenticated requests can reach the parser through content negotiation performed by HttpRequest.accepts(). The per-call length limit does not bound the combined size of repeated headers.