summaryrefslogtreecommitdiff
path: root/docs/releases/3.2.17.txt
diff options
context:
space:
mode:
Diffstat (limited to 'docs/releases/3.2.17.txt')
-rw-r--r--docs/releases/3.2.17.txt10
1 files changed, 9 insertions, 1 deletions
diff --git a/docs/releases/3.2.17.txt b/docs/releases/3.2.17.txt
index 9eba24d72f..fcc097c5cc 100644
--- a/docs/releases/3.2.17.txt
+++ b/docs/releases/3.2.17.txt
@@ -6,4 +6,12 @@ Django 3.2.17 release notes
Django 3.2.17 fixes a security issue with severity "moderate" in 3.2.16.
-...
+CVE-2023-23969: Potential denial-of-service via ``Accept-Language`` headers
+===========================================================================
+
+The parsed values of ``Accept-Language`` headers are cached in order to avoid
+repetitive parsing. This leads to a potential denial-of-service vector via
+excessive memory usage if large header values are sent.
+
+In order to avoid this vulnerability, the ``Accept-Language`` header is now
+parsed up to a maximum length.