affected: - package: ecosystem: PyPI name: django purl: pkg:pypi/django ranges: - events: - introduced: '4.2' - fixed: 4.2.30 - introduced: '5.2' - fixed: 5.2.13 - introduced: '6.0' - fixed: 6.0.4 type: ECOSYSTEM versions: - '4.2' - 4.2.1 - 4.2.10 - 4.2.11 - 4.2.12 - 4.2.13 - 4.2.14 - 4.2.15 - 4.2.16 - 4.2.17 - 4.2.18 - 4.2.19 - 4.2.2 - 4.2.20 - 4.2.21 - 4.2.22 - 4.2.23 - 4.2.24 - 4.2.25 - 4.2.26 - 4.2.27 - 4.2.28 - 4.2.29 - 4.2.3 - 4.2.4 - 4.2.5 - 4.2.6 - 4.2.7 - 4.2.8 - 4.2.9 - '5.2' - 5.2.1 - 5.2.10 - 5.2.11 - 5.2.12 - 5.2.2 - 5.2.3 - 5.2.4 - 5.2.5 - 5.2.6 - 5.2.7 - 5.2.8 - 5.2.9 - '6.0' - 6.0.1 - 6.0.2 - 6.0.3 aliases: - CVE-2026-33033 - GHSA-5mf9-h53q-7mhq details: |- An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including excessive whitespace. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue. id: PYSEC-2026-48 modified: '2026-05-20T09:18:58.648908Z' published: '2026-04-07T15:17:39.220Z' references: - type: ADVISORY url: https://groups.google.com/g/django-announce - type: FIX url: https://docs.djangoproject.com/en/dev/releases/security/ - type: FIX url: https://www.djangoproject.com/weblog/2026/apr/07/security-releases/ - type: ADVISORY url: https://github.com/advisories/GHSA-5mf9-h53q-7mhq severity: - score: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H type: CVSS_V3