Changes between Version 12 and Version 13 of SecurityTeam


Ignore:
Timestamp:
Nov 21, 2025, 6:26:48 AM (2 weeks ago)
Author:
Natalia Bidart
Comment:

Add common response for parse_header_parameters

Legend:

Unmodified
Added
Removed
Modified
  • SecurityTeam

    v12 v13  
    114114Kind regards, the Django Security Team.
    115115
    116 === Maximum password validator (lack of) ==
     116=== Maximum password validator (lack of) ===
    117117
    118118Thank you for your report. We reviewed the issue and do not consider it a security vulnerability.
     
    141141[0] https://docs.djangoproject.com/en/stable/ref/settings/#data-upload-max-memory-size
    142142
     143=== HTTP Content-Type Header parsing (parse_header_parameters) ===
     144
     145Thank you for your report. This problem has already been reported a few times in the past. The security team does not consider this to be a vulnerability, and work towards improving the handling of strings containing a large number of separators by `parse_header_parameters` has been happening in public[0]. We invite you to join this effort.
     146
     147Kind regards, the Django Security Team.
     148
     149[0] https://code.djangoproject.com/ticket/35440
     150
    143151=== Unauthenticated cache purge ===
    144152
Back to Top