In accordance with our security release policy,the Django team is issuing releases forDjango 6.1.2, Django6.0.9, and Django5.2.18.These releases address the security issues detailed below. We encourage allusers of Django to upgrade as soon as possible.CVE-2026-77050: Potential denial-of-service vulnerability in get_supported_language_variant()django.utils.translation.get_supported_language_variant() was subject toa potential denial-of-service attack when processing many distinct, very longlanguage codes. Language codes were used as keys in an in-memory cache beforetheir length was limited, potentially consuming excessive process memory.To mitigate this vulnerability, language codes longer than 500 characters arenow rejected or truncated before the cached lookup.This issue has severity "low" according to the Django security policy.Thanks to Gleb Lizunov for the report.CVE-2026-84429: Potential denial-of-service vulnerability in HTTP header parsingdjango.utils.http.parse_header_parameters() was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with many separators inside a quoted parameter. An unauthenticated request could reach this parsing through headers such as Accept or Content-Type, for instance via the content negotiation performed by HttpRequest.accepts(). The per-call length limit does not bound the combined size of repeated headers.The undocumented django.utils.http.parse_header_parameters() function now uses Python's email.message.Message for parsing. As a result, parsing of some malformed or unusual header values may differ, for example, RFC 2231 values with a missing encoding are now decoded.This issue has severity "moderate" according to the Django security policy.Thanks to Jisung Chae for the report.CVE-2026-87890: Potential request forgery via spatial lookup byte valuesSpatial lookups accepted raster values provided as bytes without requiringthem to be explicitly wrapped in django.contrib.gis.gdal.GDALRaster.Although these values were opened through GDAL's in-memory virtual filesystem,they could contain a VRT document referencing an external raster source. Thiscould cause GDAL to issue network requests as the Django process user whilepreparing the lookup.This issue could be exploited by applications that passed attacker-controlledbytes directly to a spatial lookup. It was overlooked in the fix forCVE-2026-15307.To mitigate this issue, raster values provided as bytes must now be wrappedin GDALRaster before being used in spatial lookups. Byte values representingvalid hexadecimal geometries remain accepted.This is a backward incompatible change. As a reminder, all untrusted user inputshould be validated before use.This issue has severity "moderate" according to the Django security policy.Thanks to sicksec for the report.CVE-2026-87975: Privilege abuse in model formsets with editable primary keysModel formsets incorrectly allowed forged POST data to either deleteinstances outside the limiting queryset or create instances via edit-onlyformsets when the model's primary key could be set through the form, such as with: a OneToOneField (or parent link used as the primary keyof an inline formset's model), or a natural or UUID primary key includedin the form's fields. Models using the default BigAutoField primary keywere not affected.This issue has severity "moderate" according to the Django security policy.Thanks to Seonggwon Yoon for the report.Affected supported versionsDjango mainDjango 6.1Django 6.0Django 5.2ResolutionPatches to resolve the issue have been applied to Django'smain, 6.1, 6.0, and 5.2 branches.The patches may be obtained from the following changesets.CVE-2026-77050: Potential denial-of-service vulnerability in get_supported_language_variant()On the main branchOn the 6.1 branchOn the 6.0 branchOn the 5.2 branchCVE-2026-84429: Potential denial-of-service vulnerability in HTTP header parsingOn the main branchOn the 6.1 branchOn the 6.0 branchOn the 5.2 branchCVE-2026-87890: Potential request forgery via spatial lookup byte valuesOn the main branchOn the 6.1 branchOn the 6.0 branchOn the 5.2 branchCVE-2026-87975: Privilege abuse in model formsets with editable primary keysOn the main branchOn the 6.1 branchOn the 6.0 branchOn the 5.2 branchThe following releases have been issuedDjango 6.1.2 (tarball | checksums)Django 6.0.9 (tarball | checksums)Django 5.2.18 (tarball | checksums)The PGP key ID used for this release is Sarah Boyce: 3955B19851EA96EFGeneral notes regarding security reportingAs always, we ask that potential security issues be reported via private emailto security@djangoproject.com, and not via Django's Trac instance, nor viathe Django Forum. Please seeour security policies for furtherinformation.