PT-2026-79852 · Bitnami · Django

Published

2026-08-19

·

Updated

2026-08-19

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. django.utils.translation.check for language() is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Such codes reach the function through the django.views.i18n.set language() view, which is not routed by default. The consumed memory is bounded, since request data is limited by the DATA UPLOAD MAX MEMORY SIZE setting (default 2.5 MB) and the cache holds a fixed maximum number of entries. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Jaeyoung Jang for reporting this issue.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-DJANGO-2026-15337

Affected Products

Django