CVE-2025-14550
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote attacker to cause a potential denial-of-service via a crafted request with multiple duplicate headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Jiyong Yang for reporting this issue.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 1.03%
- CWE
- CWE-407
- Published
- 2026-02-03
- Last modified
- 2026-09-17
Affected products
- djangoproject Django
- djangoproject Django
- djangoproject Django
- djangoproject Django
- djangoproject Django
- djangoproject Django
- djangoproject asgiref
- djangoproject asgiref
Weakness type
Related vulnerabilities
- CVE-2022-36021 — Redis string pattern matching can be abused to achieve Denial of Service
- CVE-2026-34573 — Parse Server: GraphQL complexity validator exponential fragment traversal DoS
- CVE-2025-64460 — Potential denial-of-service vulnerability in XML serializer text extraction
- CVE-2025-64458 — Potential denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
- CVE-2026-1285 — Potential denial-of-service vulnerability in django.utils.text.Truncator HTML methods
- CVE-2026-3276 — Potential DoS via quadratic complexity in unicodedata.normalize()
- CVE-2024-8233 — Inefficient Algorithmic Complexity in GitLab
- CVE-2022-22153 — SRX Series and MX Series with SPC3: A high percentage of fragments might lead to high latency or packet drops