← Back to browse · API

CVE-2023-24580

Severity
HIGH
CVSS
7.5
EPSS
0.62575
Risk score
51.9
CISA KEV
No
PoC
Yes
Published
2023-02-15
Modified
2025-03-18
First seen
2026-08-07
Aliases
EUVD-2023-0067, GHSA-2HRW-HX67-34X6, PYSEC-2023-13
Products
linux, n/a:n/a n/a, suse
Sources
packetstorm 2349a21bfe10b831f10dc24e|CVE-2023-24580
euvd EUVD-2023-0067

Description

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.

References