6.9
CVE-2026-77050
- EPSS 0.38%
- Veröffentlicht 06.10.2026 13:34:40
- Zuletzt bearbeitet 06.10.2026 15:17:19
- Erkennungen
Potential denial-of-service vulnerability in get_supported_language_variant()
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.translation.get_supported_language_variant()` is subject to a potential denial-of-service attack when processing many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Gleb Lizunov for reporting this issue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerdjangoproject
≫
Produkt
Django
Default Statusunaffected
Version
6.1
Version <
6.1.2
Status
affected
Version
6.1.2
Status
unaffected
Version
6.0
Version <
6.0.9
Status
affected
Version
6.0.9
Status
unaffected
Version
5.2
Version <
5.2.18
Status
affected
Version
5.2.18
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.38% | 0.3 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 | 6.9 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-789 Memory Allocation with Excessive Size Value
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
https://docs.djangoproject.com/en/dev/releases/security/
https://groups.google.com/g/django-announce
https://github.com/django/django/commit/c88b304cc2d90fc37d3bd1f5f3829706fa6c13bc
https://github.com/django/django/commit/7e878b0f8bd42260903e6a0d38996a93b0474a0b
https://github.com/django/django/commit/3d32ee80ae52745d686bf94d3555000ddf073267
https://github.com/django/django/commit/02a69e3791e3df23d45ea4ea7e7fc489f0eef2be
https://www.djangoproject.com/weblog/2026/oct/06/security-releases/