← All CVEs

CVE-2023-24580

high · 7.5

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.

7.5
CVSS
62.6%
EPSS (exploit prob.)
99th
EPSS percentile
2023-02-15
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-400

Affected products

VendorProductAffected versions
djangoprojectdjango>= 3.2, < 3.2.18
djangoprojectdjango>= 4.0, < 4.0.10
djangoprojectdjango>= 4.1, < 4.1.7
debiandebian_linux10.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-24580