Django 6.1.2, 6.0.9 and 5.2.18 Patch Four CVEs, Including a Header-Parsing Denial of Service and Formset Privilege Abuse
The Django project's October 6 security releases fix one low and three moderate issues, plus a bypass of an earlier nested-geometry mitigation; the post lists severity but no CVSS scores.
Overview
The Django project issued Django 6.1.2, 6.0.9 and 5.2.18 on October 6, 2026, according to its security release announcement, posted by Sarah Boyce. The releases address four numbered vulnerabilities and strengthen an earlier fix that did not carry a new CVE. The post states: “We encourage all users of Django to upgrade as soon as possible.”
The Django 6.1.2 release notes summarize the set as one security issue with severity “low”, three with severity “moderate”, and a fix for an insufficient security mitigation in 6.1. The announcement lists the affected supported versions as Django main, 6.1, 6.0 and 5.2, with patches applied to the main, 6.1, 6.0 and 5.2 branches.
The Four Numbered Issues
None of the four is assigned a CVSS score or vector on the announcement page or in the release notes. Django instead rates each issue under its own security policy, and the announcement records the following.
- CVE-2026-77050 (severity low), denial of service in
get_supported_language_variant(). The announcement says the function could be subject to a denial-of-service attack when processing many distinct, very long language codes, because the codes were used as keys in an in-memory cache before their length was limited, potentially consuming excessive process memory. Language codes longer than 500 characters are now rejected or truncated before the cached lookup. Credit goes to Gleb Lizunov. - CVE-2026-84429 (severity moderate), denial of service in HTTP header parsing. According to the announcement,
django.utils.http.parse_header_parameters()showed quadratic time complexity when parsing a value with many separators inside a quoted parameter. An unauthenticated request could reach this parsing through headers such as Accept or Content-Type, for instance via the content negotiation performed byHttpRequest.accepts(). The post adds that the per-call length limit does not bound the combined size of repeated headers. The fix makes the undocumented function use Python’semail.message.Messagefor parsing, so parsing of some malformed or unusual header values may differ; the post gives the example that RFC 2231 values with a missing encoding are now decoded. Credit goes to Jisung Chae. - CVE-2026-87890 (severity moderate), request forgery via spatial lookup byte values. The announcement says spatial lookups accepted raster values provided as bytes without requiring explicit wrapping in
GDALRaster, and that such values could contain a VRT document referencing an external raster source, which could cause GDAL to issue network requests as the Django process user while preparing the lookup. It says the issue could be exploited by applications that passed attacker-controlled bytes directly to a spatial lookup, and that it was overlooked in the fix for CVE-2026-15307. Raster values provided as bytes must now be wrapped inGDALRaster, while byte values representing valid hexadecimal geometries remain accepted. The post states: “This is a backward incompatible change.” Credit goes to sicksec. - CVE-2026-87975 (severity moderate), privilege abuse in model formsets with editable primary keys. Per the announcement, model formsets incorrectly allowed forged POST data to either delete instances outside the limiting queryset or create instances via edit-only formsets when the model’s primary key could be set through the form, such as with a OneToOneField, or a natural or UUID primary key included in the form’s fields. The post states: “Models using the default BigAutoField primary key were not affected.” Credit goes to Seonggwon Yoon.
Follow-up to CVE-2026-15830
The fifth item is a follow-up rather than a new vulnerability. The announcement says the mitigation for CVE-2026-15830, a denial-of-service issue involving nested geometry collections, could be bypassed by certain WKB geometries, allowing deeply nested geometries to reach GEOS, and that the update does not introduce a new CVE but strengthens the original fix. It credits blacknianthejdan, the Kimi Security Team and David Sarkisyan. The Django security archive dates CVE-2026-15830 to August 4, 2026, and notes an additional hardening published with the October 6 patch releases.
The 6.1.2 release notes say the new algorithm treats WKB and WKT inputs more consistently and also fixes a rare case where a valid geometry could have been rejected.
Upgrade Notes
Two of the fixes change behavior. The header-parsing change can alter how unusual header values are interpreted, and the spatial-lookup change requires code that passes raw bytes to a spatial lookup to wrap them in GDALRaster first. The announcement adds a reminder that all untrusted user input should be validated before use.
The announcement names no mitigations other than the code changes in the fixed releases, and it does not describe any exploitation in the wild. The security archive lists the four October 6 CVEs as patched in Django 6.1, 6.0 and 5.2. The announcement also states that the PGP key used for the releases is Sarah Boyce’s, with key ID 3955B19851EA96EF, and repeats the project’s request that potential security issues be reported by private email to [email protected] rather than through Trac or the Django Forum.
What We Don’t Know
The announcement does not give CVSS scores, so numerical comparisons with other projects’ advisories are not possible from the primary sources reviewed. This article relied on Django’s own announcement, release notes and security archive; the National Vulnerability Database entries could not be retrieved at the time of writing, so no independent scoring was checked.