Vulnerabilities
Vulnerable Software
Security Vulnerabilities
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Such codes reach the function through the `django.views.i18n.set_language()` view, which is not routed by default. The consumed memory is bounded, since request data is limited by the `DATA_UPLOAD_MAX_MEMORY_SIZE` setting (default 2.5 MB) and the cache holds a fixed maximum number of entries. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Jaeyoung Jang for reporting this issue.
CVSS Score
6.9
EPSS Score
0.005
Published
2026-08-04
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue.
CVSS Score
6.9
EPSS Score
0.005
Published
2026-08-04
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
CVSS Score
7.6
EPSS Score
0.001
Published
2026-08-04
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-08-04
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
CVSS Score
7.5
EPSS Score
0.001
Published
2026-08-04
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
CVSS Score
7.4
EPSS Score
0.001
Published
2026-08-04
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
CVSS Score
9.6
EPSS Score
0.001
Published
2026-08-04
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
CVSS Score
6.5
EPSS Score
0.001
Published
2026-08-04
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVSS Score
6.5
EPSS Score
0.001
Published
2026-08-04
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
CVSS Score
8.1
EPSS Score
0.001
Published
2026-08-04


Contact Us

Shodan ® - All rights reserved