CVE-2026-15337
Description
A flaw was found in Django. A remote attacker could trigger a denial-of-service (DoS) condition by sending many distinct, very long language codes to the django.utils.translation.check_for_language() function. These codes are stored in an in-memory cache, leading to excessive memory consumption. While the memory usage is bounded by configuration settings, this vulnerability could still impact system availability.
Statement
Moderate: This denial-of-service vulnerability in Django arises from excessive memory consumption when processing specially crafted, long language codes. The impact is mitigated in Red Hat products as the affected django.views.i18n.set_language() view is not routed by default, limiting exposure to this flaw. Exploitation would require explicit routing of this view within a Django application.
Mitigation
To mitigate this issue, ensure that the `django.views.i18n.set_language()` view remains unrouted in Django applications. If custom routing exposes this view, restrict access to trusted networks or implement input validation to limit the length and number of language codes processed.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 5.3 | N/A | 5.3 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | Low | N/A | Low |
| Privileges Required | None | N/A | None |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | None | N/A | None |
| Integrity Impact | None | N/A | None |
| Availability Impact | Low | N/A | Low |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other); Reduce Performance
This issue can make the product perform more slowly. If an attacker can influence the number of iterations in the loop, then this performance problem might allow a denial of service by consuming more platform resources than intended.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.