IsItPatchedInstant security status for any software version
← All products

CVE-2014-0481

MEDIUM severity · CVSS 4.3 · CWE-399
4.3CVSS MEDIUM

Summary

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.

Impact & exploitability

Attack vectorNetwork
Attack complexity
Privileges required
User interaction
Confidentiality impactNone
Integrity impactNone
Availability impact
Exploit probability (EPSS)1%

AV:N/AC:M/Au:N/C:N/I:N/A:P

Affected products we track (2)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: https://www.djangoproject.com/weblog/2014/aug/20/security/ ↗

Last checked: Wed, 10 Jun 2026 22:18:30 UTC