CVE-2026-77050
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.translation.get_supported_language_variant()` is subject to a potential denial-of-service attack when processing many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Gleb Lizunov for reporting this issue.
- CVSS
- 6.9
- EPSS
- —
- CISA KEV
- Not listed
- Exploitation
- none
- Public exploits
- None seen
- State
- PUBLISHED
Coverage
Framework blogs: Next.js releases / Svelte / Angular / Django / Rails / Laravel / Spring / React Native / FlutterAuthoritative. Authoritative publisher: a primary source, or a newsroom with formal editorial standards
Django security releases issued: 6.1.2, 6.0.9, and 5.2.18
In accordance with our security release policy, the Django team is issuing releases for Django 6.1.2, Django 6.0.9, and Django 5.2.18. These releases address the security issues detailed below. We encourage all users of Django to upgrade as soon as possible. CVE-2026-77050: Potential…
What we observed
No signals recorded