-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 04 Aug 2026 15:57:59 -0700 Source: python-django Built-For-Profiles: nocheck Architecture: source Version: 3:5.2.17-1 Distribution: unstable Urgency: high Maintainer: Debian Python Team <team+python@tracker.debian.org> Changed-By: Chris Lamb <lamby@debian.org> Closes: 1143611 Changes: python-django (3:5.2.17-1) unstable; urgency=high . * New upstream security release: . - CVE-2026-15307: Prevent a server-side file-write and request forgery via geoospatial lookups. Spatial lookups allowed str and dict lookup values to be passed to the GDALRaster class when they represented rasters. Depending on the raster driver, this could write a file to disk (in some cases enabling remote code execution) or issue a network request as the Django process user. Because the Django admin changelist permits filtering via ModelAdmin.lookup_allowed(), the flaw was reachable by staff users with view permissions on any registered model containing a spatial field. . Dictionaries and strings that are not valid GEOSGeometry instances, e.g. a serialized dictionary are now disallowed by spatial lookups. (This is a backward incompatible change.) . - CVE-2026-15337: Avoid a potential denial-of-service vulnerability in the check_for_language() method in the django.utils.translation method. This was subject to a potential denial-of-service (DoS) attack when checking many distinct, very long language codes. Each code was used as a key in an in-memory cache, consuming process memory. . The language value reaches this function through the set_language() view of django.views.i18n (which is not active by default) from POST data. Since request data is limited by the DATA_UPLOAD_MAX_MEMORY_SIZE setting and the cache is configured to store a maximum number of entries, the memory that could be consumed was bounded. To mitigate this vulnerability, language codes longer than 500 characters are now rejected before the cached lookup. . - CVE-2026-15830: Prevent a potential denial-of-service vulnerability via nested geometry collections. GEOSGeometry was subject to a potential denial-of-service attack when provided deeply nested GEOMETRYCOLLECTION objects leading to a segmentation fault in GEOS. A maximum depth of 198 GEOMETRYCOLLECTIONs is now enforced for the well-known text (WKT) format and a maximum number of 198 GEOMETRYCOLLECTIONs in total (breadth and depth) is enforced for well-known binaries (WKB). Lookups against spatial fields and the GeometryField form field were also affected. . - CVE-2026-15920: Prevnt a potential cross-site scripting (XSS) attack via URLField values in the Django admin. The admin renders URLField values as clickable links on changelist views and read-only fields. The link was generated without validating the value as a safe URL, so a stored value using a potentially dangerous scheme was rendered as a link. URLField values shown via display_for_field are now validated using URLValidator before a link is rendered and displayed as plain text if validation is failed. . (Closes: #1143611) . <https://www.djangoproject.com/weblog/2026/aug/04/security-releases/> . * Bump debhelper compatibility level to 13. Checksums-Sha1: 83c09400adc8bb93238b4622da945e177e062332 2790 python-django_5.2.17-1.dsc 7c0ecfdec9fdd9c3dcc1e96be06dbd6841beee3b 10889740 python-django_5.2.17.orig.tar.gz bd6e733573eac179e34f0d3f09b12f7304854e7e 39640 python-django_5.2.17-1.debian.tar.xz 4d32107b31a6ffe5d32c6305764fe4183547ed65 8227 python-django_5.2.17-1_amd64.buildinfo Checksums-Sha256: dacc146732b44f03d75b62bb4284c4b1fab0b8e6d2d6ccc70c6c0347df465212 2790 python-django_5.2.17-1.dsc 9d4d93be539a18ab80d058eb515900e10951e04c537c5a6b394fc49528d3251f 10889740 python-django_5.2.17.orig.tar.gz 31019458a8800ce2876b82a7e5a087ac6454ca4cee618586ea370627dcddf860 39640 python-django_5.2.17-1.debian.tar.xz 3bd37d3f3735b3c7b137c876cb94ec6d76319b9a005843b824bd269b005f2ecb 8227 python-django_5.2.17-1_amd64.buildinfo Files: dd0ea56833bf913480f806ba78db832f 2790 python optional python-django_5.2.17-1.dsc d3e9f9ca5c6d7d044a97675def960297 10889740 python optional python-django_5.2.17.orig.tar.gz 0f11b054f81f0d93bd2b6d98d1ba3ae0 39640 python optional python-django_5.2.17-1.debian.tar.xz b3ad2ae6cbd28cd57bc8d1fe22da78aa 8227 python optional python-django_5.2.17-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmpydeYACgkQHpU+J9Qx HlgghRAAlnkZmVxlgboDQgFlPGkT4QFkeLNJUMZndlgabuNiUJFEOad6kx9zjcDy efkkZ/X7FPQEzywblK+YOxPnppn5tETRaroDYwF5+a+ti/2s5ChHQIWTU8iM/Q6Z LQsIVUjvf5xG+ykyOx2r1usm0xvfG2kDCtqM738e9qED2LQi/TgIv8PTLhc/Bb0A vXY2MKfJNGMNPbZNjV4Igdpimmc5iGTVdQ/5nzBgmRm4LtlfEsy0tU/PKiYs4CcK 7Ni2MTq9DNBiZGbvr18JCNh2xjY6wR6xiGouR0MKEPqY9yDJ/lI47XjkwKVYQz+o eYWSu4R1ozNLR5zKiO/sAMXuGorhZzxuVLrHID6NZ425IUPI52K18GpIDbpDfGDk Pdmc4L9PijBNEmbjRETdKhbB3vtDIZgo4oT/4hxXbu2+sM42g+YCKQSnanI5Of8a rR+zIWsyNcLhbIccvlhWtutfZXsvdLrLfvYPtSpYucU8fPwIZvNKnYNkT4HbIqov cSYXX05R4uIi6Mxrszv3+J+uAtEk7OU/HYcQCcR2YojyajW7+/kQcGGx1WHc4qow A5WeGEdlNYWz42aQrCeqyqHiEAqPFldr57ncFN4ctRa6m89p3XZMbKx5tw5mdzm4 LrMyNZtjGCc0l68qCidahDx7Jyspm9JGFeUb9bK30pi0QPjM5X0= =bbVZ -----END PGP SIGNATURE-----