Back

HIGH

ASGI header spoofing via underscore/hyphen conflation

Published Apr 7, 2026

Description

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (11)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner DSF
Published Apr 7, 2026
Updated Apr 7, 2026
Reserved Mar 10, 2026

CISA Vulnrichment

Updated Apr 7, 2026

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Apr 7, 2026
Bugzilla 2455935

ENISA EUVD

Assigner DSF
Published Apr 7, 2026
Updated Apr 7, 2026