CVE-2026-15337

Source
https://cve.org/CVERecord?id=CVE-2026-15337
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15337.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-15337
Downstream
Related
Published
2026-08-04T15:48:25.817Z
Modified
2026-08-07T10:12:02.497487350Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Potential denial-of-service vulnerability in check_for_language()
Details

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. django.utils.translation.check_for_language() is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Such codes reach the function through the django.views.i18n.set_language() view, which is not routed by default. The consumed memory is bounded, since request data is limited by the DATA_UPLOAD_MAX_MEMORY_SIZE setting (default 2.5 MB) and the cache holds a fixed maximum number of entries. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Jaeyoung Jang for reporting this issue.

Database specific
{
    "cna_assigner": "DSF",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15337.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "6.0"
                },
                {
                    "fixed": "6.0.8"
                },
                {
                    "introduced": "5.2"
                },
                {
                    "fixed": "5.2.17"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "5.2"
                },
                {
                    "fixed": "5.2.17"
                },
                {
                    "introduced": "6.0"
                },
                {
                    "fixed": "6.0.8"
                }
            ],
            "source": "DESCRIPTION"
        }
    ],
    "cwe_ids": [
        "CWE-789"
    ]
}
References

Affected packages

Git / github.com/django/django

Affected ranges

Type
GIT
Repo
https://github.com/django/django
Events
Database specific
{
    "source": "REFERENCES"
}

Affected versions

1.*
1.0
1.1
1.2
1.2.1
1.3
1.4
1.7a2
5.*
5.2
5.2.1
5.2.10
5.2.11
5.2.12
5.2.13
5.2.14
5.2.15
5.2.16
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
5.2a1
5.2b1
5.2rc1
6.*
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0a1
6.0b1
6.0rc1
6.1a1
6.1b1
6.1rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15337.json"