CVE-2023-23969: Debian Linux

High severity, CVSS 7.5. EPSS: 47.4% chance of exploitation in the next 30 days.

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Djangoproject Django: from 3.2, before 3.2.17 (fixed in 3.2.17); from 4.0, before 4.0.9 (fixed in 4.0.9); from 4.1, before 4.1.6 (fixed in 4.1.6)

Published 2023-02-01. Last modified 2026-06-17.