Description
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gutenberg Blocks by WordPress Download Manager Cross-Site Scripting (2.1.8)
WordPress Plugin EZ Portfolio Multiple Cross-Site Scripting Vulnerabilities (1.0.1)
MySQL CVE-2018-3185 Vulnerability (CVE-2018-3185)
WordPress Plugin SEO by Squirrly SEO Multiple Unspecified Vulnerabilities (6.1.4)