The middleware chain in use is for valid web pages. But the 404 page should not require CSRF (It should only serve HEAD and GET requests).