Denial-of-Service Vulnerability in Django Framework
CVE-2026-77050

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-77050?

A potential denial-of-service vulnerability exists in the Django framework affecting several versions due to the improper handling of multiple long language codes in the django.utils.translation.get_supported_language_variant() function. When processing a high volume of distinct, lengthy language codes, the application retains these codes as keys in an in-memory cache, which can lead to excessive memory consumption and potentially disrupt service. Unsanctioned older versions may also be impacted.

Affected Version(s)

Django 6.1 < 6.1.2

Django 6.0 < 6.0.9

Django 5.2 < 5.2.18

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gleb Lizunov
Sarah Boyce
Sarah Boyce
.