CVE-2026-15337
published 2026-08-04CVE-2026-15337: An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.03%
61.6th percentile
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
`django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Such codes reach the function through the `django.views.i18n.set_language()` view, which is not routed by default. The consumed memory is bounded, since request data is limited by the `DATA_UPLOAD_MAX_MEMORY_SIZE` setting (default 2.5 MB) and the cache holds a fixed maximum number of entries.
Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.
Django would like to thank Jaeyoung Jang for reporting this issue.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-24 | controller-rhel8 | — | — |
| ansible-automation-platform-24 | eda-controller-rhel8 | — | — |
| ansible-automation-platform-24 | hub-rhel8 | — | — |
| ansible-automation-platform-24 | lightspeed-rhel8 | — | — |
| ansible-automation-platform-25 | ansible-dev-tools-rhel8 | — | — |
| ansible-automation-platform-25 | controller-rhel8 | — | — |
| ansible-automation-platform-25 | eda-controller-rhel8 | — | — |
| ansible-automation-platform-25 | gateway-rhel8 | — | — |
| ansible-automation-platform-25 | hub-rhel8 | — | — |
| ansible-automation-platform-25 | lightspeed-rhel8 | — | — |
| ansible-automation-platform-26 | ansible-dev-tools-rhel9 | — | — |
| ansible-automation-platform-26 | controller-rhel9 | — | — |
| ansible-automation-platform-26 | eda-controller-rhel9 | — | — |
| ansible-automation-platform-26 | gateway-rhel9 | — | — |
| ansible-automation-platform-26 | hub-rhel9 | — | — |
| ansible-automation-platform-26 | lightspeed-rhel9 | — | — |
| ansible-automation-platform-27 | aap-cloud-billing-rhel9 | — | — |
| ansible-automation-platform-27 | ansible-dev-tools-rhel9 | — | — |
| ansible-automation-platform-27 | controller-rhel9 | — | — |
| ansible-automation-platform-27 | eda-controller-rhel9 | — | — |
| ansible-automation-platform-27 | gateway-rhel9 | — | — |
| ansible-automation-platform-27 | hub-rhel9 | — | — |
| ansible-automation-platform-27 | lightspeed-rhel9 | — | — |
| ansible-automation-platform-27 | metrics-service-rhel9 | — | — |
| ansible-automation-platform-tech-preview | metrics-service-rhel9 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
ghsa_unreviewed·2026-08-04
CVE-2026-15337 [MEDIUM] CWE-789 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
`django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Such codes reach the function through the `django.views.i18n.set_language()` view, which is not routed by default. The consumed memory is bounded, since request data is limited by the `DATA_UPLOAD_MAX_MEMORY_SIZE` setting (default 2.5 MB) and the cache holds a fixed maximum number of entries.
Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.
Django would like to thank Jaeyoung Jang for reporting this issue.
Red Hat
django: Django: Denial-of-service vulnerability due to excessive memory consumption
vendor_redhat·2026-08-04·CVSS 5.3
CVE-2026-15337 [MEDIUM] CWE-1050 django: Django: Denial-of-service vulnerability due to excessive memory consumption
django: Django: Denial-of-service vulnerability due to excessive memory consumption
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
`django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Such codes reach the function through the `django.views.i18n.set_language()` view, which is not routed by default. The consumed memory is bounded, since request data is limited by the `DATA_UPLOAD_MAX_MEMORY_SIZE` setting (default 2.5 MB) and the cache holds a fixed maximum number of entries.
Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.
Djang
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
blogs_hackernews·2026-08-31
CVE-2026-81578 ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
The boring parts caused most of the trouble.
A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional.
Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept things moving. Different attacks, same useful mistake: something familiar was trusted without a second look.
Here is the week...
## ⚡ Threat of the
Hackernews
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
blogs_hackernews·2026-08-05·CVSS 9.5
CVE-2026-58073 [CRITICAL] Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django.
The three most serious:
An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5
A cross-tenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users' requests, scored a maximum 10.0 on its CVE record
A flaw in GeoDjango's spatial lookups that can write a file to disk and, on some setups, run code, rea
Wiz
CVE-2025-15337 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-15337 [MEDIUM] CVE-2025-15337 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15337 :
NixOS vulnerability analysis and mitigation
Tanium addressed an incorrect default permissions vulnerability in Patch.
Source : NVD
## 6.5
Score
Published February 5, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
patch
Sources
NVD
Nix Severity MEDIUM Has Fix Added at: Feb 11, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related NixOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploi
Bugzilla
CVE-2026-15337 python-django6: Django: Denial-of-service vulnerability due to excessive memory consumption [fedora-all]
bugzilla·2026-08-09·CVSS 5.3
CVE-2026-15337 [MEDIUM] CVE-2026-15337 python-django6: Django: Denial-of-service vulnerability due to excessive memory consumption [fedora-all]
CVE-2026-15337 python-django6: Django: Denial-of-service vulnerability due to excessive memory consumption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
`django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Such codes reach the function through the `django.views.i18n.set_language()` view, which is not routed by default. The consumed memory is bounded, since
Bugzilla
CVE-2026-15337 python-django5: Django: Denial-of-service vulnerability due to excessive memory consumption [fedora-all]
bugzilla·2026-08-09·CVSS 5.3
CVE-2026-15337 [MEDIUM] CVE-2026-15337 python-django5: Django: Denial-of-service vulnerability due to excessive memory consumption [fedora-all]
CVE-2026-15337 python-django5: Django: Denial-of-service vulnerability due to excessive memory consumption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
`django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Such codes reach the function through the `django.views.i18n.set_language()` view, which is not routed by default. The consumed memory is bounded, since
Bugzilla
CVE-2026-15337 python-django4.2: Django: Denial-of-service vulnerability due to excessive memory consumption [epel-all]
bugzilla·2026-08-09·CVSS 5.3
CVE-2026-15337 [MEDIUM] CVE-2026-15337 python-django4.2: Django: Denial-of-service vulnerability due to excessive memory consumption [epel-all]
CVE-2026-15337 python-django4.2: Django: Denial-of-service vulnerability due to excessive memory consumption [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
`django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Such codes reach the function through the `django.views.i18n.set_language()` view, which is not routed by default. The consumed memory is bounded, since
Bugzilla
CVE-2026-15337 django: Django: Denial-of-service vulnerability due to excessive memory consumption
bugzilla·2026-08-04·CVSS 5.3
CVE-2026-15337 [MEDIUM] CVE-2026-15337 django: Django: Denial-of-service vulnerability due to excessive memory consumption
CVE-2026-15337 django: Django: Denial-of-service vulnerability due to excessive memory consumption
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
`django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Such codes reach the function through the `django.views.i18n.set_language()` view, which is not routed by default. The consumed memory is bounded, since request data is limited by the `DATA_UPLOAD_MAX_MEMORY_SIZE` setting (default 2.5 MB) and the cache holds a fixed maximum number of entries.
Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be
https://docs.djangoproject.com/en/dev/releases/security/https://github.com/django/django/commit/224dbc832586ad5cfb0237c2ff30d14baeaddc6fhttps://github.com/django/django/commit/27137e655e442e81095f1f8f77ff3870d9fdf169https://github.com/django/django/commit/5b3523d29be25948e1dd90b3863a002f00fc865fhttps://github.com/django/django/commit/c72a5dbb64d0777f3f471f1be94e8b2ca91e0959https://groups.google.com/g/django-announcehttps://www.djangoproject.com/weblog/2026/aug/04/security-releases/
2026-08-04
Published