Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.9 PyPI

Django vulnerable to Denial of Service via i18n middleware component

GHSA-9v8h-57gv-qch6 · CVE-2007-5712 · PYSEC-2007-1

Published · Modified

Description

The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows remote attackers to cause a denial of service (memory consumption) via many HTTP requests with large Accept-Language headers.

Ready to move

Start Securing

Free, no credit card | First findings in minutes