CVE-2026-15337

Description

A flaw was found in Django. A remote attacker could trigger a denial-of-service (DoS) condition by sending many distinct, very long language codes to the django.utils.translation.check_for_language() function. These codes are stored in an in-memory cache, leading to excessive memory consumption. While the memory usage is bounded by configuration settings, this vulnerability could still impact system availability.

Statement

Moderate: This denial-of-service vulnerability in Django arises from excessive memory consumption when processing specially crafted, long language codes. The impact is mitigated in Red Hat products as the affected django.views.i18n.set_language() view is not routed by default, limiting exposure to this flaw. Exploitation would require explicit routing of this view within a Django application.

Mitigation

To mitigate this issue, ensure that the `django.views.i18n.set_language()` view remains unrouted in Django applications. If custom routing exposes this view, restrict access to trusted networks or implement input validation to limit the length and number of language codes processed.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score5.3N/A5.3
Attack VectorNetworkN/ANetwork
Attack ComplexityLowN/ALow
Privileges RequiredNoneN/ANone
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityNoneN/ANone
Integrity ImpactNoneN/ANone
Availability ImpactLowN/ALow

Vector

Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other); Reduce Performance

This issue can make the product perform more slowly. If an attacker can influence the number of iterations in the loop, then this performance problem might allow a denial of service by consuming more platform resources than intended.

Frequently Asked Questions

Want to get errata notifications? Sign up here.