Detects Django instances running under ASGI where ASGIRequest normalizes header names by converting hyphens to underscores, allowing an attacker to spoof security-sensitive headers by supplying the underscore variant (e.g., X_Forwarded_Host instead of X-Forwarded-Host). This bypasses reverse proxy header stripping and lets an attacker forge the client IP, host, and protocol. The fix ignores headers with underscores entirely. Update to Django 6.0.4, 5.2.13, or 4.2.30.
Is your app exploitable through CVE-2026-3902?
Scan your domain free