CVE-2026-33033Disclosure(djangoproject / django)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch djangoproject django systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including excessive whitespace. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-407

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • django

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 3 mentions (2026-04-07); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
django

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-04-07: 3Mentions · 2026-04-14: 1Mentions · 2026-04-15: 1Mentions · 2026-04-17: 1PoC Mentioned / Linked · 2026-04-14: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-07: 3Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-17: 104-0704-1404-1504-17
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-073
Disclosure3
2026-04-141
Patch1
2026-04-151
Disclosure1
2026-04-171
Disclosure1
Full discourse6 posts
  • GeekNews@GeekNewsHada
    Disclosure

    단 20MB HTTP 패킷으로 Django 서버를 1분간 먹통 만드는 취약점이 공개되었습니다 (CVE-2026-33033) 전체 한 줄 요약 Django의 `MultiPartParser`에서 `Content-Transfer-Encoding: base64` 파트 본문이 공백 위주일 때 발생하는 Pre-Auth CPU exhaustion 취약점으… https://news.hada.io/topic?id=28512

    Post summary

    A newly disclosed CVE‑2026‑33033 describes a pre‑authentication CPU exhaustion attack in Django’s MultiPartParser triggered by a 20 MB HTTP multipart payload encoded in base64 that is primarily whitespace, potentially shutting the server down for about a minute.

    01111683.4K
    27.9K followersView on X
  • Seokchan Yoon / 윤석찬@_seokchan_yoon
    Patch

    🚨 Django Developers — Urgent Alert! Django developers, even with completely default settings, your application can be affected by a Pre-Auth DoS vulnerability (CVE-2026-33033). A single 20MB HTTP POST data is enough to lock up one worker's CPU for a full minute through MultiPartParser base64 whitespace abuse. Detailed technical analysis and PoC explanation are available here: https://new-blog.ch4n3.kr/django-pre-auth-denial-of-service-en/ Please update to Django 6.0.4, 5.2.13 or 4.2.30 ASAP!

    Post summary

    The note announces a Pre‑Auth DoS vulnerability (CVE‑2026‑33033), provides PoC details, and urges users to upgrade to patched Django releases.

    0301721.8K
    737 followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Django CVE-2026-33033: DoS in MultiPartParser via base64-encoded file upload CVE-2026-33034: DoS in ASGI requests via memory upload limit bypass

    Post summary

    The post announces two new DoS vulnerabilities in Django: one affecting MultiPartParser with base64‑encoded file uploads and another exploiting ASGI's memory upload limit bypass. No PoC, exploit tool, active exploitation, or patch is referenced.

    00010408
    4.4K followersView on X
  • _inside@J_zjaan7946
    Disclosure

    CVE-2026-33033: Django 파일 업로드 처리기 DoS 취약점 https://blog.naver.com/inside-j/224252555196

    Post summary

    A new denial‑of‑service vulnerability affecting Django’s file upload processor (CVE-2026-33033) has been announced via a blog post. No proof‑of‑concept, exploit code, or patch information is provided in the notice.

    0000049
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33033 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote attackers to degrade performance by submitting … https://www.cve.org/CVERecord?id=CVE-2026-33033 ----- Traducción: CVE-2026-33033 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-33033 in specific software releases, describing it as a remote performance‑degradation issue via MultiPartParser, without providing PoC, exploit, or mitigation details.

    0000030
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33033 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote attackers to degrade performance by submitting … https://www.cve.org/CVERecord?id=CVE-2026-33033

    Post summary

    The post announces a performance‑degradation vulnerability in `MultiPartParser` affecting multiple software versions, with no indication of PoCs, active exploitation, or available patches.

    00000169
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdjangoprojectdjango---

Explore more