티스토리 수익 글 보기
{{ message }}
Django has an Improper Handling of Length Parameter Inconsistency
Moderate severity
GitHub Reviewed
Published
May 5, 2026
to the GitHub Advisory Database
•
Updated Jun 6, 2026
Package
Affected versions
>= 6.0, < 6.0.5
>= 5.2, < 5.2.14
Patched versions
6.0.5
5.2.14
Description
Published by the National Vulnerability Database
May 5, 2026
Published to the GitHub Advisory Database
May 5, 2026
Reviewed
May 8, 2026
Last updated
Jun 6, 2026
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated
Content-Lengthheader can bypass theFILE_UPLOAD_MAX_MEMORY_SIZElimit, potentially loading large files into memory and causing service degradation.As a reminder, Django expects a limit to be configured at the web server level rather than solely relying on
FILE_UPLOAD_MAX_MEMORY_SIZE. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.Django thanks Kyle Agronick for reporting this issue.
References