๐Ÿ” CVE Alert

CVE-2026-77050

MEDIUM 5.3

Potential denial-of-service vulnerability in get_supported_language_variant()

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.translation.get_supported_language_variant()` is subject to a potential denial-of-service attack when processing many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Gleb Lizunov for reporting this issue.

CWE CWE-789
Vendor djangoproject
Product django
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for djangoproject django

Be the first to know when new medium vulnerabilities affecting djangoproject django are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

djangoproject / Django
6.1 < 6.1.2 6.0 < 6.0.9 5.2 < 5.2.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.djangoproject.com: https://docs.djangoproject.com/en/dev/releases/security/ groups.google.com: https://groups.google.com/g/django-announce github.com: https://github.com/django/django/commit/c88b304cc2d90fc37d3bd1f5f3829706fa6c13bc github.com: https://github.com/django/django/commit/7e878b0f8bd42260903e6a0d38996a93b0474a0b github.com: https://github.com/django/django/commit/3d32ee80ae52745d686bf94d3555000ddf073267 github.com: https://github.com/django/django/commit/02a69e3791e3df23d45ea4ea7e7fc489f0eef2be djangoproject.com: https://www.djangoproject.com/weblog/2026/oct/06/security-releases/

Credits

๐Ÿ” Gleb Lizunov Sarah Boyce Sarah Boyce