CVE-2026-33034Disclosure(djangoproject / django)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • django

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-07); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
django

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-07: 3Mentions · 2026-04-10: 1Mentions · 2026-04-19: 1Technical Details · 2026-04-07: 3Technical Details · 2026-04-19: 104-0704-1004-19
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-073
Disclosure3
2026-04-101
General1
2026-04-191
General1
Full discourse5 posts
  • PulsePatch.io@pulsepatchio
    General

    `Django` vulnerability `CVE-2026-33034` allows `DATA_UPLOAD_MAX_MEMORY_SIZE` bypass via SGI `Content-Length` manipulation, risking resource exhaustion. Monitor `Django` project updates for patches. #Django #WebSecurity #CVE https://www.pulsepatch.io/posts/cve-2026-33034-django-content-length-bypass

    Post summary

    The tweet announces CVE-2026-33034, outlining a bypass of Django’s data upload size limit through SGI Content-Length manipulation, but it does not provide any PoC, exploit code, active exploitation evidence, or patch details.

    00002103
    12 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Django ❗ CVE-2026-3902 ❗ CVE-2026-33034 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-django-2/ https://t.co/Y4RdtjMbku

    Post summary

    The tweet lists two CVE identifiers for Django products and provides links for additional information, but contains no further details or actionable content.

    00010101
    6.6K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Django CVE-2026-33033: DoS in MultiPartParser via base64-encoded file upload CVE-2026-33034: DoS in ASGI requests via memory upload limit bypass

    Post summary

    The text announces two new Django CVEs (CVE‑2026‑33033 and CVE‑2026‑33034) describing DoS vulnerabilities related to file uploads and memory limit bypasses.

    00010408
    4.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33034 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypa… https://www.cve.org/CVERecord?id=CVE-2026-33034 ----- Traducción: CVE-2026-33034 Se d… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-33034 as a new vulnerability affecting several major software versions, citing a missing `Content-Length` header as the issue, but does not provide any PoC, exploit, or patch details.

    0000027
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33034 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypa… https://www.cve.org/CVERecord?id=CVE-2026-33034

    Post summary

    The CVE is disclosed with affected version details and a brief context of the flaw, but no PoC, exploit, active exploitation, or patch information is provided.

    00000157
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdjangoprojectdjango---

Explore more