The Django team has issued security releases for Django versions 6.1.2, 6.0.9, and 5.2.18. These updates address multiple security vulnerabilities and users are encouraged to upgrade their installations promptly to mitigate potential risks.
CVE-2026-77050 addresses a potential denial-of-service (DoS) vulnerability in `django.utils.translation.get_supported_language_variant()`. This issue arose when processing numerous distinct, very long language codes, which could consume excessive memory due to their use as keys in an in-memory cache. The fix involves rejecting or truncating language codes longer than 500 characters before cached lookups, preventing memory exhaustion. This vulnerability was rated as 'low' severity by Django's security policy.
Another denial-of-service vulnerability, CVE-2026-84429, was found in `django.utils.http.parse_header_parameters()`. This vulnerability stemmed from quadratic time complexity when parsing values with many separators inside a quoted parameter, which could be triggered by unauthenticated requests through headers like `Accept` or `Content-Type`. The `parse_header_parameters()` function now uses Python's `email.message.Message` for parsing, which resolves the issue. This vulnerability was rated as 'moderate' severity.
CVE-2026-87890 addresses a potential request forgery vulnerability related to spatial lookups. Previously, spatial lookups accepted raster values provided as bytes without requiring explicit wrapping in `django.contrib.gis.gdal.GDALRaster`. This allowed for the inclusion of VRT documents referencing external raster sources, potentially causing GDAL to issue network requests as the Django process user. This could be exploited by applications passing attacker-controlled bytes directly to a spatial lookup.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Django team released security updates 6.1.2, 6.0.9, and 5.2.18 to address several vulnerabilities, including potential denial-of-service issues and a request forgery vulnerability. These updates are critical for maintaining the security and stability of Django applications.