CVE-2026-33034
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.
- Djangoproject Django
- < 4.2.30, 5.2.13, 6.0.4
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.8% (52th percentile)
- Weakness
- CWE-770
- NVD status
- Analyzed
- Published
- 2026-04-07
- Attack patterns
- CAPEC-130
CVE-2026-33034 at NVD
No indexed exploits for CVE-2026-33034 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-33034 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.