← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Django Releases Security Updates 6.1.2, 6.0.9, and 5.2.18 Addressing Multiple CVEs

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Django released versions 6.1.2, 6.0.9, and 5.2.18.
  • CVE-2026-77050 fixed a DoS in language variant processing.
  • CVE-2026-84429 fixed a DoS in HTTP header parsing.
  • CVE-2026-87890 fixed potential request forgery via spatial lookups.

Security Releases Issued

The Django team has issued security releases for Django versions 6.1.2, 6.0.9, and 5.2.18. These updates address multiple security vulnerabilities and users are encouraged to upgrade their installations promptly to mitigate potential risks.

Denial-of-Service Vulnerability in Language Processing

CVE-2026-77050 addresses a potential denial-of-service (DoS) vulnerability in `django.utils.translation.get_supported_language_variant()`. This issue arose when processing numerous distinct, very long language codes, which could consume excessive memory due to their use as keys in an in-memory cache. The fix involves rejecting or truncating language codes longer than 500 characters before cached lookups, preventing memory exhaustion. This vulnerability was rated as 'low' severity by Django's security policy.

HTTP Header Parsing DoS Vulnerability

Another denial-of-service vulnerability, CVE-2026-84429, was found in `django.utils.http.parse_header_parameters()`. This vulnerability stemmed from quadratic time complexity when parsing values with many separators inside a quoted parameter, which could be triggered by unauthenticated requests through headers like `Accept` or `Content-Type`. The `parse_header_parameters()` function now uses Python's `email.message.Message` for parsing, which resolves the issue. This vulnerability was rated as 'moderate' severity.

Request Forgery via Spatial Lookups

CVE-2026-87890 addresses a potential request forgery vulnerability related to spatial lookups. Previously, spatial lookups accepted raster values provided as bytes without requiring explicit wrapping in `django.contrib.gis.gdal.GDALRaster`. This allowed for the inclusion of VRT documents referencing external raster sources, potentially causing GDAL to issue network requests as the Django process user. This could be exploited by applications passing attacker-controlled bytes directly to a spatial lookup.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~4 min · 3 stories · Oct 06

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The Django team released security updates 6.1.2, 6.0.9, and 5.2.18 to address several vulnerabilities, including potential denial-of-service issues and a request forgery vulnerability. These updates are critical for maintaining the security and stability of Django applications.