Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-23969
Description:In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.
Test IDs: 1.3.6.1.4.1.25623.1.0.893306   1.3.6.1.4.1.25623.1.1.12.2023.5837.2   1.3.6.1.4.1.25623.1.1.12.2023.5837.1   1.3.6.1.4.1.25623.1.0.127320   1.3.6.1.4.1.25623.1.0.127319  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-23969
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HWY6DQWRVBALV73BPUVBXC3QIYUM24IK/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LTZVAKU5ALQWOKFTPISE257VCVIYGFQI/
https://docs.djangoproject.com/en/4.1/releases/security/
https://groups.google.com/forum/#!forum/django-announce
https://lists.debian.org/debian-lts-announce/2023/02/msg00000.html




© 1998-2025 E-Soft Inc. All rights reserved.