---
id: CVE-2026-77050
title: "An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18.\n`django.utils.translation.get_supported_language_variant()` is subject to\r\na potential denial-of-service attack when processing many distinct, v…"
summary: "An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18.\n`django.utils.translation.get_supported_language_variant()` is subject to\r\na potential denial-of-service attack when processing many distinct, v…"
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-789
vendor: djangoproject
product: django
affected:
  - django >= 6.1 < 6.1.2
  - django >= 6.0 < 6.0.9
  - django >= 5.2 < 5.2.18
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T15:17:19.377'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77050'
references:
  - url: 'https://docs.djangoproject.com/en/dev/releases/security/'
    label: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
  - url: >-
      https://github.com/django/django/commit/02a69e3791e3df23d45ea4ea7e7fc489f0eef2be
    label: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
  - url: >-
      https://github.com/django/django/commit/3d32ee80ae52745d686bf94d3555000ddf073267
    label: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
  - url: >-
      https://github.com/django/django/commit/7e878b0f8bd42260903e6a0d38996a93b0474a0b
    label: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
  - url: >-
      https://github.com/django/django/commit/c88b304cc2d90fc37d3bd1f5f3829706fa6c13bc
    label: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
  - url: 'https://groups.google.com/g/django-announce'
    label: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
  - url: 'https://www.djangoproject.com/weblog/2026/oct/06/security-releases/'
    label: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-06T14:20:18.760413Z'
ingestedAt: '2026-10-06T14:00:19.150Z'
---

## Overview

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18.
`django.utils.translation.get_supported_language_variant()` is subject to
a potential denial-of-service attack when processing many distinct, very long
language codes, which are retained as keys in an in-memory cache and
consume process memory.
Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.
Django would like to thank Gleb Lizunov for reporting this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
