-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 06 Oct 2026 08:14:09 -0700
Source: python-django
Built-For-Profiles: nocheck
Architecture: source
Version: 3:6.1.2-1
Distribution: experimental
Urgency: high
Maintainer: Debian Python Team <[email protected]>
Changed-By: Chris Lamb <[email protected]>
Closes: 1150176
Changes:
 python-django (3:6.1.2-1) experimental; urgency=high
 .
   * New upstream security release:
 .
     - CVE-2026-77050: Potential denial-of-service vulnerability in
       get_supported_language_variant. This method was subject to a potential
       denial-of-service attack when processing many distinct and very long
       language codes. Language codes were used as keys in an in-memory cache
       before their length was limited, potentially consuming excessive process
       memory. To mitigate this vulnerability, language codes longer than 500
       characters are now rejected or truncated before the cached lookup.
 .
     - CVE-2026-84429: Potential denial-of-service vulnerability in HTTP header
       parsing. django.utils.http.parse_header_parameters() was subject to a
       potential denial-of-service attack due to quadratic time complexity when
       parsing a value with many separators inside a quoted parameter. An
       unauthenticated request could reach this through common headers such as
       Accept or Content-Type, for instance via the content negotiation
       performed by HttpRequest.accepts(). The per-call length limit does not
       bound the combined size of repeated headers. The undocumented
       django.utils.http.parse_header_parameters() function now uses Python's
       email.message.Message for parsing. As a result, parsing of some malformed
       or unusual header values may differ, for example, RFC 2231 values with a
       missing encoding are now decoded.
 .
     - CVE-2026-87890: Potential request forgery via spatial lookup byte values.
       Spatial lookups accepted raster values provided as bytes without
       requiring them to be explicitly wrapped in django.contrib.gis.gdal's
       GDALRaster. Although these values were opened through GDAL's in-memory
       virtual filesystem, they could contain a VRT document referencing an
       external raster source. This could cause GDAL to issue network requests
       as the Django process user while preparing the lookup. This issue could
       be exploited by applications that passed attacker-controlled bytes
       directly to a spatial lookup. This was overlooked in the fix for
       CVE-2026-15307. To mitigate this issue, raster values provided as bytes
       must now be wrapped in GDALRaster before being used in spatial lookups.
       Byte values representing valid hexadecimal geometries remain accepted.
       This is a backward incompatible change.
 .
     - CVE-2026-87975: Prevent privilege abuse in model formsets with editable
       primary keys. Model formsets incorrectly allowed forged POST data to
       either delete instances outside the limiting queryset or create instances
       via edit-only formsets when the model's primary key could be set through
       the form, such as with a OneToOneField (or parent link used as the
       primary key of an inline formset's model), or a natural or UUID primary
       key included in the form's fields. Models using the default BigAutoField
       primary key were not affected.
 .
     <https://www.djangoproject.com/weblog/2026/oct/06/security-releases/>
 .
     (Closes: #1150176)
Checksums-Sha1:
 75c2db8fb311ec4e1ebc4c2875294e0651041758 2783 python-django_6.1.2-1.dsc
 933b451da0f4f1605cbbad01e1a00f535b4a73a3 11251425 
python-django_6.1.2.orig.tar.gz
 e69e47946c428054f4f34ed06b122ae2b8bfd080 34312 
python-django_6.1.2-1.debian.tar.xz
 4ff2ffa9d55f1f26cd6a70ee8b35278964bf1df6 7723 
python-django_6.1.2-1_amd64.buildinfo
Checksums-Sha256:
 01082304b925eda9d165ea2cf7b16f5a1ff99cae7f5adabb30a526b4c5ab47d2 2783 
python-django_6.1.2-1.dsc
 a1e92451ccb8b514e91bbb3b6d186d20b4030558f116b5d9de6535455ff210b7 11251425 
python-django_6.1.2.orig.tar.gz
 2e0818e96d0f5dbb54d17537350049630ed3cd680e8408aed680f6c45b134b1e 34312 
python-django_6.1.2-1.debian.tar.xz
 86a8935096f0188e1e569f00d2df9a41570a0d2a2e6e333b7f48863d5084ad2f 7723 
python-django_6.1.2-1_amd64.buildinfo
Files:
 72a56685817867c3cf6c9961f0af5403 2783 python optional python-django_6.1.2-1.dsc
 7c2461ccfcea3d11464ef207fa0bcbed 11251425 python optional 
python-django_6.1.2.orig.tar.gz
 d67b475d2e3e7f0140119456ee735171 34312 python optional 
python-django_6.1.2-1.debian.tar.xz
 b1046398fd664d95641fdcf82296da43 7723 python optional 
python-django_6.1.2-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmrFE7AACgkQHpU+J9Qx
HlheLhAAjmhigfsQh7uhSFUaeO8Z6uEH2AehbG3WgGWOyy9NyY6cnhEPdUHvdKou
qPM4uxrerZpbRVg2LvEJWit3B1NkN4B4CRcuEG/fkzFDXoj5otlpKsJlLFVEgUlb
64oJJ56vtSKqrm6J1fJHwO10sfTc3EYOvDsxJdPM0U9locO15ziXbflCw9My/BwT
gZ8Gtr6aYeE+sJ9DkS8KXJ1iFEHIxetBk9aAzf/qkjpJkgJGAw7+Grnhd9KhgP+g
vHFPv0tFPcrvtVXNkhyPPgVUMYxRIVVLTOmzUPyxkY8mEodUyQmbmoQ3iyS5KFAq
U14ft+ALnWdGiaeFLWlBx0KGbOAaLle5gmywmgRFxRq1g4P+48OiuPhFnzrgqQDp
7/4iAS/BH0L/3ChxD9RRRxMrueRYqwAdZLZznJibHadRLmAWYqlS2OLZGZBZ6WB8
GoYTfzZf6wTaVniDVHl569g5sr6ohNE41TzZyb7LlWz/l/F0J+DQP0KEkPWMxGNa
bPYLDMozw97IAVvBFobS1ri8tWCoZJ2l9GFJeC6NyTD0ZdIwyqRe2dDr42VTLDKe
UVLUi56Z4ldvzJlc79muBjv6YV7AnW4vHHMDN0fsYMd/UjCZv8xbR4JZ9pyqHTDk
NKfD3tuhehJN8s5m8nkV1Nzi6ulcAR8bfdh83JkU5nZurvLasYY=
=ESwJ
-----END PGP SIGNATURE-----

Attachment: pgpFF29EYU9FH.pgp
Description: PGP signature

Reply via email to