-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 05 Oct 2026 12:27:32 -0700 Source: python-django Binary: python-django-doc python3-django Architecture: source all Version: 3:5.2.17-2~bpo13+1 Distribution: trixie-backports Urgency: high Maintainer: Debian Python Team <team+python@tracker.debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: python-django-doc - High-level Python web development framework (documentation) python3-django - High-level Python web development framework Closes: 1143611 1145438 Changes: python-django (3:5.2.17-2~bpo13+1) trixie-backports; urgency=medium . * Rebuild for trixie-backports. * Refresh patches. . python-django (3:5.2.17-2) unstable; urgency=medium . * Apply a number of upstream patches to address FTBFS issues under Python 3.15. Thanks to Maximiliano Curia (maxy) for report and research: . - "Used annotation_format parameter of getfullargspec() on Python 3.15." - "Defaulted suggest_on_error=True in management commands." - "Fixed test_invalid_choice_db_option on Python 3.14.5+." - Drop incorrect/masked definition of htmlparser_fixed_security in tests/utils_tests/test_html.py. . (Closes: #1145438) . python-django (3:5.2.17-1) unstable; urgency=high . * New upstream security release: . - CVE-2026-15307: Prevent a server-side file-write and request forgery via geoospatial lookups. Spatial lookups allowed str and dict lookup values to be passed to the GDALRaster class when they represented rasters. Depending on the raster driver, this could write a file to disk (in some cases enabling remote code execution) or issue a network request as the Django process user. Because the Django admin changelist permits filtering via ModelAdmin.lookup_allowed(), the flaw was reachable by staff users with view permissions on any registered model containing a spatial field. . Dictionaries and strings that are not valid GEOSGeometry instances, e.g. a serialized dictionary are now disallowed by spatial lookups. (This is a backward incompatible change.) . - CVE-2026-15337: Avoid a potential denial-of-service vulnerability in the check_for_language() method in the django.utils.translation method. This was subject to a potential denial-of-service (DoS) attack when checking many distinct, very long language codes. Each code was used as a key in an in-memory cache, consuming process memory. . The language value reaches this function through the set_language() view of django.views.i18n (which is not active by default) from POST data. Since request data is limited by the DATA_UPLOAD_MAX_MEMORY_SIZE setting and the cache is configured to store a maximum number of entries, the memory that could be consumed was bounded. To mitigate this vulnerability, language codes longer than 500 characters are now rejected before the cached lookup. . - CVE-2026-15830: Prevent a potential denial-of-service vulnerability via nested geometry collections. GEOSGeometry was subject to a potential denial-of-service attack when provided deeply nested GEOMETRYCOLLECTION objects leading to a segmentation fault in GEOS. A maximum depth of 198 GEOMETRYCOLLECTIONs is now enforced for the well-known text (WKT) format and a maximum number of 198 GEOMETRYCOLLECTIONs in total (breadth and depth) is enforced for well-known binaries (WKB). Lookups against spatial fields and the GeometryField form field were also affected. . - CVE-2026-15920: Prevnt a potential cross-site scripting (XSS) attack via URLField values in the Django admin. The admin renders URLField values as clickable links on changelist views and read-only fields. The link was generated without validating the value as a safe URL, so a stored value using a potentially dangerous scheme was rendered as a link. URLField values shown via display_for_field are now validated using URLValidator before a link is rendered and displayed as plain text if validation is failed. . (Closes: #1143611) . <https://www.djangoproject.com/weblog/2026/aug/04/security-releases/> . * Bump debhelper compatibility level to 13. Checksums-Sha1: f19a03abf1b093dd9f0ef08c470104d362622da9 2824 python-django_5.2.17-2~bpo13+1.dsc 7c0ecfdec9fdd9c3dcc1e96be06dbd6841beee3b 10889740 python-django_5.2.17.orig.tar.gz 1f51e8dab015c4a970caa7f88795aea7ae906199 43380 python-django_5.2.17-2~bpo13+1.debian.tar.xz a03ed5999873435004db4640521ea325104bdbf8 3027028 python-django-doc_5.2.17-2~bpo13+1_all.deb 14f51ce2d319ceda78c92af9b0680276414dbd69 16931 python-django_5.2.17-2~bpo13+1_amd64.buildinfo de5ea936983cde4d1712b5d79b4919abba65b78f 2901124 python3-django_5.2.17-2~bpo13+1_all.deb Checksums-Sha256: e421296e93a05d5c802683713ddc8db544db4be8c2bdaabc0632d03b2edd5586 2824 python-django_5.2.17-2~bpo13+1.dsc 9d4d93be539a18ab80d058eb515900e10951e04c537c5a6b394fc49528d3251f 10889740 python-django_5.2.17.orig.tar.gz 01ef7fa91d74d27d0de9abe03c3fddd1799f053e819cdeec6e1bf7e138565c61 43380 python-django_5.2.17-2~bpo13+1.debian.tar.xz cc7fea460cdfcf15924640e7915f340f9d3bb729983f10ab767853e8ff2f19f1 3027028 python-django-doc_5.2.17-2~bpo13+1_all.deb 3d136b2f410ef1406af4e34b10bc5a91a96c232cee3f7de597d38754967af832 16931 python-django_5.2.17-2~bpo13+1_amd64.buildinfo 14b73b0f535c000d793a54e2aa4294b5bf89f035863165bd565cd9ce2c014b1f 2901124 python3-django_5.2.17-2~bpo13+1_all.deb Files: 5f98c830f5b5e8bca1057db3bdce6a01 2824 python optional python-django_5.2.17-2~bpo13+1.dsc d3e9f9ca5c6d7d044a97675def960297 10889740 python optional python-django_5.2.17.orig.tar.gz d62762ad772bdba094624454179612e0 43380 python optional python-django_5.2.17-2~bpo13+1.debian.tar.xz 3abd8d69a9f93ae3c543a4d8fef1ca9a 3027028 doc optional python-django-doc_5.2.17-2~bpo13+1_all.deb c8b5c09cd239ef71cc180cf7fcd44b8d 16931 python optional python-django_5.2.17-2~bpo13+1_amd64.buildinfo 2a7cc1564884231248f860b6d0e3ea5d 2901124 python optional python3-django_5.2.17-2~bpo13+1_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmrD/jUACgkQHpU+J9Qx HlgwKRAAsbyY31AaxmDMzttziMx3LfqZS3uZbEZauWPXpsQ4d0v6qOidmNP1672w R69VDeuz4TSNi0KrzrQPaFM3ZQ7UfesYNUdgo38Wc8GLrEg5HNJLKtpHAwmxDJOf QhTDhab5BRijD6co67F3Okb9bE6m9/7j6py/U/u9MrflQM8VwdOzLMmRw0avWT/U 953DbtLt7pWuGpoy4rbD55bWxJ6BQ4wB3ZCAKKZbctVG8nI9bHFYbkS/+VtzIL3S 3wGr6dRKGXJwxcL4MoZgHUDVxzkeOkNlw351/FlENy4VZxjyY+qDZn9I6ttMG7VW JTl5Gqul/bq5+1Xnk5cBryvyATggC3E8TSvLseRtJ71x7MHRnzntsxWPlkHUmmLC PRdSAfhducw/2e+GYnuyGC34Q0N8I6YGJyzcf+esyg7VTFTE5trE6BHnACSvEWwB xKBVzf2X1yWE+eDGeaQIAgVkcZS1BxKk2b4NMuJakIaEBB/i+reXo+/vNxQVE3KX Jd8rCqyoClsiE/D1f2/8nP4ScgJzL9FztAlUyfqsq04+IXGZg4UeGYJdKYx4KWz1 gVmPGkRqK4M87S5GzA5AiFBvYVGv+KtrtfRUZ+lBu0YWekPtxtUYd9Aek96RN1xp RwIvH6BU4k5pjhvKCjaSpUIt2QQ4YE5dXIkzV390jLvCOB9Dtvw= =wTWA -----END PGP SIGNATURE-----