Accepted python-django 3:5.2.17-1 (source) into unstable

Debian FTP Masters <[email protected]> Tue, 04 Aug 2026 23:34:05 +0000
Newsgroups gmane.linux.debian.devel.changes.unstable
Message-ID <[email protected]>
--===============5378295820661389299==
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 04 Aug 2026 15:57:59 -0700
Source: python-django
Built-For-Profiles: nocheck
Architecture: source
Version: 3:5.2.17-1
Distribution: unstable
Urgency: high
Maintainer: Debian Python Team <[email protected]>
Changed-By: Chris Lamb <[email protected]>
Closes: 1143611
Changes:
 python-django (3:5.2.17-1) unstable; urgency=3Dhigh
 .
   * New upstream security release:
 .
     - CVE-2026-15307: Prevent a server-side file-write and request forgery v=
ia
       geoospatial lookups. Spatial lookups allowed str and dict lookup values
       to be passed to the GDALRaster class when they represented rasters.
       Depending on the raster driver, this could write a file to disk (in so=
me
       cases enabling remote code execution) or issue a network request as the
       Django process user. Because the Django admin changelist permits
       filtering via ModelAdmin.lookup_allowed(), the flaw was reachable by
       staff users with view permissions on any registered model containing a
       spatial field.
 .
       Dictionaries and strings that are not valid GEOSGeometry instances, e.=
g.
       a serialized dictionary are now disallowed by spatial lookups. (This i=
s a
       backward incompatible change.)
 .
     - CVE-2026-15337: Avoid a potential denial-of-service vulnerability in t=
he
       check_for_language() method in the django.utils.translation method. Th=
is
       was subject to a potential denial-of-service (DoS) attack when checking
       many distinct, very long language codes. Each code was used as a key in
       an in-memory cache, consuming process memory.
 .
       The language value reaches this function through the set_language() vi=
ew
       of django.views.i18n (which is not active by default) from POST data.
       Since request data is limited by the DATA_UPLOAD_MAX_MEMORY_SIZE setti=
ng
       and the cache is configured to store a maximum number of entries, the
       memory that could be consumed was bounded. To mitigate this
       vulnerability, language codes longer than 500 characters are now rejec=
ted
       before the cached lookup.
 .
     - CVE-2026-15830: Prevent a potential denial-of-service vulnerability via
       nested geometry collections. GEOSGeometry was subject to a potential
       denial-of-service attack when provided deeply nested GEOMETRYCOLLECTION
       objects leading to a segmentation fault in GEOS. A maximum depth of 198
       GEOMETRYCOLLECTIONs is now enforced for the well-known text (WKT) form=
at
       and a maximum number of 198 GEOMETRYCOLLECTIONs in total (breadth and
       depth) is enforced for well-known binaries (WKB). Lookups against spat=
ial
       fields and the GeometryField form field were also affected.
 .
     - CVE-2026-15920: Prevnt a potential cross-site scripting (XSS) attack v=
ia
       URLField values in the Django admin. The admin renders URLField values=
 as
       clickable links on changelist views and read-only fields. The link was
       generated without validating the value as a safe URL, so a stored value
       using a potentially dangerous scheme was rendered as a link. URLField
       values shown via display_for_field are now validated using URLValidator
       before a link is rendered and displayed as plain text if validation is
       failed.
 .
     (Closes: #1143611)
 .
     <https://www.djangoproject.com/weblog/2026/aug/04/security-releases/>
 .
   * Bump debhelper compatibility level to 13.
Checksums-Sha1:
 83c09400adc8bb93238b4622da945e177e062332 2790 python-django_5.2.17-1.dsc
 7c0ecfdec9fdd9c3dcc1e96be06dbd6841beee3b 10889740 python-django_5.2.17.orig.=
tar.gz
 bd6e733573eac179e34f0d3f09b12f7304854e7e 39640 python-django_5.2.17-1.debian=
.tar.xz
 4d32107b31a6ffe5d32c6305764fe4183547ed65 8227 python-django_5.2.17-1_amd64.b=
uildinfo
Checksums-Sha256:
 dacc146732b44f03d75b62bb4284c4b1fab0b8e6d2d6ccc70c6c0347df465212 2790 python=
-django_5.2.17-1.dsc
 9d4d93be539a18ab80d058eb515900e10951e04c537c5a6b394fc49528d3251f 10889740 py=
thon-django_5.2.17.orig.tar.gz
 31019458a8800ce2876b82a7e5a087ac6454ca4cee618586ea370627dcddf860 39640 pytho=
n-django_5.2.17-1.debian.tar.xz
 3bd37d3f3735b3c7b137c876cb94ec6d76319b9a005843b824bd269b005f2ecb 8227 python=
-django_5.2.17-1_amd64.buildinfo
Files:
 dd0ea56833bf913480f806ba78db832f 2790 python optional python-django_5.2.17-1=
.dsc
 d3e9f9ca5c6d7d044a97675def960297 10889740 python optional python-django_5.2.=
17.orig.tar.gz
 0f11b054f81f0d93bd2b6d98d1ba3ae0 39640 python optional python-django_5.2.17-=
1.debian.tar.xz
 b3ad2ae6cbd28cd57bc8d1fe22da78aa 8227 python optional python-django_5.2.17-1=
_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmpydeYACgkQHpU+J9Qx
HlgghRAAlnkZmVxlgboDQgFlPGkT4QFkeLNJUMZndlgabuNiUJFEOad6kx9zjcDy
efkkZ/X7FPQEzywblK+YOxPnppn5tETRaroDYwF5+a+ti/2s5ChHQIWTU8iM/Q6Z
LQsIVUjvf5xG+ykyOx2r1usm0xvfG2kDCtqM738e9qED2LQi/TgIv8PTLhc/Bb0A
vXY2MKfJNGMNPbZNjV4Igdpimmc5iGTVdQ/5nzBgmRm4LtlfEsy0tU/PKiYs4CcK
7Ni2MTq9DNBiZGbvr18JCNh2xjY6wR6xiGouR0MKEPqY9yDJ/lI47XjkwKVYQz+o
eYWSu4R1ozNLR5zKiO/sAMXuGorhZzxuVLrHID6NZ425IUPI52K18GpIDbpDfGDk
Pdmc4L9PijBNEmbjRETdKhbB3vtDIZgo4oT/4hxXbu2+sM42g+YCKQSnanI5Of8a
rR+zIWsyNcLhbIccvlhWtutfZXsvdLrLfvYPtSpYucU8fPwIZvNKnYNkT4HbIqov
cSYXX05R4uIi6Mxrszv3+J+uAtEk7OU/HYcQCcR2YojyajW7+/kQcGGx1WHc4qow
A5WeGEdlNYWz42aQrCeqyqHiEAqPFldr57ncFN4ctRa6m89p3XZMbKx5tw5mdzm4
LrMyNZtjGCc0l68qCidahDx7Jyspm9JGFeUb9bK30pi0QPjM5X0=3D
=3DbbVZ
-----END PGP SIGNATURE-----


--===============5378295820661389299==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCanJ27QAKCRCb9qggYcy5
IWvpAQD3bTNV3aF4iXH3+6up/f6072Hg0O/5iTNEOke/xuFFjAD/fcmQff6mH0NB
zva/FqFOEIxibmISuxo5t9Dkwo5uTwc=
=ur6I
-----END PGP SIGNATURE-----

--===============5378295820661389299==--