CVE-2026-77050
Deferred Deferred - Pending Action

Denial-of-Service in Django via Language Variant Processing

Vulnerability report for CVE-2026-77050, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: Django Software Foundation

Description

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.translation.get_supported_language_variant()` is subject to a potential denial-of-service attack when processing many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Gleb Lizunov for reporting this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
djangoproject Django 6.1
djangoproject Django 6.0
djangoproject Django 5.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial-of-service issue in Django versions 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. It occurs when the function django.utils.translation.get_supported_language_variant() processes many distinct, very long language codes. These codes are stored in an in-memory cache, consuming excessive process memory and potentially crashing the system.

Detection Guidance

To detect this vulnerability, check your Django version using 'python -c "import django; print(django.get_version())"'. If you are running Django 6.1 before 6.1.2, 6.0 before 6.0.9, or 5.2 before 5.2.18, or any unsupported series like 5.1.x, 5.0.x, or 4.2.x, your system may be affected.

Impact Analysis

This vulnerability can cause system slowdowns or crashes due to excessive memory consumption. Attackers could exploit it by sending requests with many long language codes, leading to resource exhaustion and denial of service for legitimate users.

Mitigation Strategies

Immediately upgrade to a patched version of Django: 6.1.2, 6.0.9, or 5.2.18. If using an unsupported series, upgrade to a supported version or apply relevant patches if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77050. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart