Accepted python-django 3:5.2.17-1 (source) into unstable
Debian FTP Masters <[email protected]> Tue, 04 Aug 2026 23:34:05 +0000
| Newsgroups | gmane.linux.debian.devel.changes.unstable |
|---|---|
| Message-ID | <[email protected]> |
--===============5378295820661389299== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 04 Aug 2026 15:57:59 -0700 Source: python-django Built-For-Profiles: nocheck Architecture: source Version: 3:5.2.17-1 Distribution: unstable Urgency: high Maintainer: Debian Python Team <[email protected]> Changed-By: Chris Lamb <[email protected]> Closes: 1143611 Changes: python-django (3:5.2.17-1) unstable; urgency=3Dhigh . * New upstream security release: . - CVE-2026-15307: Prevent a server-side file-write and request forgery v= ia geoospatial lookups. Spatial lookups allowed str and dict lookup values to be passed to the GDALRaster class when they represented rasters. Depending on the raster driver, this could write a file to disk (in so= me cases enabling remote code execution) or issue a network request as the Django process user. Because the Django admin changelist permits filtering via ModelAdmin.lookup_allowed(), the flaw was reachable by staff users with view permissions on any registered model containing a spatial field. . Dictionaries and strings that are not valid GEOSGeometry instances, e.= g. a serialized dictionary are now disallowed by spatial lookups. (This i= s a backward incompatible change.) . - CVE-2026-15337: Avoid a potential denial-of-service vulnerability in t= he check_for_language() method in the django.utils.translation method. Th= is was subject to a potential denial-of-service (DoS) attack when checking many distinct, very long language codes. Each code was used as a key in an in-memory cache, consuming process memory. . The language value reaches this function through the set_language() vi= ew of django.views.i18n (which is not active by default) from POST data. Since request data is limited by the DATA_UPLOAD_MAX_MEMORY_SIZE setti= ng and the cache is configured to store a maximum number of entries, the memory that could be consumed was bounded. To mitigate this vulnerability, language codes longer than 500 characters are now rejec= ted before the cached lookup. . - CVE-2026-15830: Prevent a potential denial-of-service vulnerability via nested geometry collections. GEOSGeometry was subject to a potential denial-of-service attack when provided deeply nested GEOMETRYCOLLECTION objects leading to a segmentation fault in GEOS. A maximum depth of 198 GEOMETRYCOLLECTIONs is now enforced for the well-known text (WKT) form= at and a maximum number of 198 GEOMETRYCOLLECTIONs in total (breadth and depth) is enforced for well-known binaries (WKB). Lookups against spat= ial fields and the GeometryField form field were also affected. . - CVE-2026-15920: Prevnt a potential cross-site scripting (XSS) attack v= ia URLField values in the Django admin. The admin renders URLField values= as clickable links on changelist views and read-only fields. The link was generated without validating the value as a safe URL, so a stored value using a potentially dangerous scheme was rendered as a link. URLField values shown via display_for_field are now validated using URLValidator before a link is rendered and displayed as plain text if validation is failed. . (Closes: #1143611) . <https://www.djangoproject.com/weblog/2026/aug/04/security-releases/> . * Bump debhelper compatibility level to 13. Checksums-Sha1: 83c09400adc8bb93238b4622da945e177e062332 2790 python-django_5.2.17-1.dsc 7c0ecfdec9fdd9c3dcc1e96be06dbd6841beee3b 10889740 python-django_5.2.17.orig.= tar.gz bd6e733573eac179e34f0d3f09b12f7304854e7e 39640 python-django_5.2.17-1.debian= .tar.xz 4d32107b31a6ffe5d32c6305764fe4183547ed65 8227 python-django_5.2.17-1_amd64.b= uildinfo Checksums-Sha256: dacc146732b44f03d75b62bb4284c4b1fab0b8e6d2d6ccc70c6c0347df465212 2790 python= -django_5.2.17-1.dsc 9d4d93be539a18ab80d058eb515900e10951e04c537c5a6b394fc49528d3251f 10889740 py= thon-django_5.2.17.orig.tar.gz 31019458a8800ce2876b82a7e5a087ac6454ca4cee618586ea370627dcddf860 39640 pytho= n-django_5.2.17-1.debian.tar.xz 3bd37d3f3735b3c7b137c876cb94ec6d76319b9a005843b824bd269b005f2ecb 8227 python= -django_5.2.17-1_amd64.buildinfo Files: dd0ea56833bf913480f806ba78db832f 2790 python optional python-django_5.2.17-1= .dsc d3e9f9ca5c6d7d044a97675def960297 10889740 python optional python-django_5.2.= 17.orig.tar.gz 0f11b054f81f0d93bd2b6d98d1ba3ae0 39640 python optional python-django_5.2.17-= 1.debian.tar.xz b3ad2ae6cbd28cd57bc8d1fe22da78aa 8227 python optional python-django_5.2.17-1= _amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmpydeYACgkQHpU+J9Qx HlgghRAAlnkZmVxlgboDQgFlPGkT4QFkeLNJUMZndlgabuNiUJFEOad6kx9zjcDy efkkZ/X7FPQEzywblK+YOxPnppn5tETRaroDYwF5+a+ti/2s5ChHQIWTU8iM/Q6Z LQsIVUjvf5xG+ykyOx2r1usm0xvfG2kDCtqM738e9qED2LQi/TgIv8PTLhc/Bb0A vXY2MKfJNGMNPbZNjV4Igdpimmc5iGTVdQ/5nzBgmRm4LtlfEsy0tU/PKiYs4CcK 7Ni2MTq9DNBiZGbvr18JCNh2xjY6wR6xiGouR0MKEPqY9yDJ/lI47XjkwKVYQz+o eYWSu4R1ozNLR5zKiO/sAMXuGorhZzxuVLrHID6NZ425IUPI52K18GpIDbpDfGDk Pdmc4L9PijBNEmbjRETdKhbB3vtDIZgo4oT/4hxXbu2+sM42g+YCKQSnanI5Of8a rR+zIWsyNcLhbIccvlhWtutfZXsvdLrLfvYPtSpYucU8fPwIZvNKnYNkT4HbIqov cSYXX05R4uIi6Mxrszv3+J+uAtEk7OU/HYcQCcR2YojyajW7+/kQcGGx1WHc4qow A5WeGEdlNYWz42aQrCeqyqHiEAqPFldr57ncFN4ctRa6m89p3XZMbKx5tw5mdzm4 LrMyNZtjGCc0l68qCidahDx7Jyspm9JGFeUb9bK30pi0QPjM5X0=3D =3DbbVZ -----END PGP SIGNATURE----- --===============5378295820661389299== Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCanJ27QAKCRCb9qggYcy5 IWvpAQD3bTNV3aF4iXH3+6up/f6072Hg0O/5iTNEOke/xuFFjAD/fcmQff6mH0NB zva/FqFOEIxibmISuxo5t9Dkwo5uTwc= =ur6I -----END PGP SIGNATURE----- --===============5378295820661389299==--