← Back to CVE List
CVE-2026-77050NVD
Vulnerability Summary
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18.
`django.utils.translation.get_supported_language_variant()` is subject to
a potential denial-of-service attack when processing many distinct, very long
language codes, which are retained as keys in an in-memory cache and
consume process memory.
Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.
Django would like to thank Gleb Lizunov for reporting this issue.
`django.utils.translation.get_supported_language_variant()` is subject to
a potential denial-of-service attack when processing many distinct, very long
language codes, which are retained as keys in an in-memory cache and
consume process memory.
Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.
Django would like to thank Gleb Lizunov for reporting this issue.
CVSS v4.0 Base Metrics — Score 6.9 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 5.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityLow
Affected & Patched Versions
- djangoproject Django >= 6.1 and < 6.1.2
- djangoproject Django >= 6.0 and < 6.0.9
- djangoproject Django >= 5.2 and < 5.2.18
- djangoproject Django 6.1.2
- djangoproject Django 6.0.9
- djangoproject Django 5.2.18
External References
- https://docs.djangoproject.com/en/dev/releases/security/
- https://groups.google.com/g/django-announce
- https://github.com/django/django/commit/c88b304cc2d90fc37d3bd1f5f3829706fa6c13bc
- https://github.com/django/django/commit/7e878b0f8bd42260903e6a0d38996a93b0474a0b
- https://github.com/django/django/commit/3d32ee80ae52745d686bf94d3555000ddf073267
- https://github.com/django/django/commit/02a69e3791e3df23d45ea4ea7e7fc489f0eef2be
- https://www.djangoproject.com/weblog/2026/oct/06/security-releases/