CVE-2025-14550Inefficient Algorithmic Complexity in Django

Severity
7.5HIGHNVD
OSV5.3
EPSS
0.1%
top 80.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 3

Description

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote attacker to cause a potential denial-of-service via a crafted request with multiple duplicate headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Jiyong Yang for reporting this issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

CVEListV5djangoproject/django6.06.0.2+2
NVDdjangoproject/django4.24.2.28+2
PyPIdjangoproject/django6.0a16.0.2+2
CVEListV5djangoproject/asgiref33.11.1

Patches

🔴Vulnerability Details

5
OSV
python-django vulnerabilities2026-02-03
OSV
CVE-2025-14550: An issue was discovered in 62026-02-03
GHSA
Django has Inefficient Algorithmic Complexity2026-02-03
OSV
Django has Inefficient Algorithmic Complexity2026-02-03
CVEList
Potential denial-of-service vulnerability via repeated headers when using ASGI2026-02-03

📋Vendor Advisories

3
Red Hat
Django: Django: Denial of Service via crafted request with duplicate headers2026-02-03
Ubuntu
Django vulnerabilities2026-02-03
Debian
CVE-2025-14550: python-django - An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4...2025

🕵️Threat Intelligence

1
Wiz
CVE-2025-14550 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-14550 — Inefficient Algorithmic Complexity | cvebase