CVE-2025-14550: Potential denial-of-service vulnerability via repeated headers when using ASGI
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
ASGIRequest allows a remote attacker to cause a potential denial-of-service via a crafted request with multiple duplicate headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Jiyong Yang for reporting this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/Djangoto a version that resolves this vulnerability.Fixed in 4.2.28 - Upgrade
Upgrade
pip/Djangoto a version that resolves this vulnerability.Fixed in 5.2.11 - Upgrade
Upgrade
pip/Djangoto a version that resolves this vulnerability.Fixed in 6.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14550?
CVE-2025-14550 is classified as a potential denial-of-service vulnerability.
How do I fix CVE-2025-14550?
To fix CVE-2025-14550, update Django to version 4.2.28, 5.2.11, or 6.0.2.
Which versions of Django are affected by CVE-2025-14550?
Django versions prior to 6.0.2, 5.2.11, and 4.2.28 are affected by CVE-2025-14550.
What type of attack does CVE-2025-14550 allow?
CVE-2025-14550 allows a remote attacker to potentially carry out a denial-of-service attack via crafted requests with multiple duplicate headers.
When was CVE-2025-14550 discovered?
CVE-2025-14550 was discovered in versions of Django before 6.0.2, 5.2.11, and 4.2.28.