-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 06 Oct 2026 08:36:10 -0700 Source: python-django Built-For-Profiles: nocheck Architecture: source Version: 3:5.2.18-1 Distribution: unstable Urgency: high Maintainer: Debian Python Team <team+python@tracker.debian.org> Changed-By: Chris Lamb <lamby@debian.org> Closes: 1150176 Changes: python-django (3:5.2.18-1) unstable; urgency=high . * New upstream security release: . - CVE-2026-77050: Potential denial-of-service vulnerability in get_supported_language_variant. This method was subject to a potential denial-of-service attack when processing many distinct and very long language codes. Language codes were used as keys in an in-memory cache before their length was limited, potentially consuming excessive process memory. To mitigate this vulnerability, language codes longer than 500 characters are now rejected or truncated before the cached lookup. . - CVE-2026-84429: Potential denial-of-service vulnerability in HTTP header parsing. django.utils.http.parse_header_parameters() was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with many separators inside a quoted parameter. An unauthenticated request could reach this through common headers such as Accept or Content-Type, for instance via the content negotiation performed by HttpRequest.accepts(). The per-call length limit does not bound the combined size of repeated headers. The undocumented django.utils.http.parse_header_parameters() function now uses Python's email.message.Message for parsing. As a result, parsing of some malformed or unusual header values may differ, for example, RFC 2231 values with a missing encoding are now decoded. . - CVE-2026-87890: Potential request forgery via spatial lookup byte values. Spatial lookups accepted raster values provided as bytes without requiring them to be explicitly wrapped in django.contrib.gis.gdal's GDALRaster. Although these values were opened through GDAL's in-memory virtual filesystem, they could contain a VRT document referencing an external raster source. This could cause GDAL to issue network requests as the Django process user while preparing the lookup. This issue could be exploited by applications that passed attacker-controlled bytes directly to a spatial lookup. This was overlooked in the fix for CVE-2026-15307. To mitigate this issue, raster values provided as bytes must now be wrapped in GDALRaster before being used in spatial lookups. Byte values representing valid hexadecimal geometries remain accepted. This is a backward incompatible change. . - CVE-2026-87975: Prevent privilege abuse in model formsets with editable primary keys. Model formsets incorrectly allowed forged POST data to either delete instances outside the limiting queryset or create instances via edit-only formsets when the model's primary key could be set through the form, such as with a OneToOneField (or parent link used as the primary key of an inline formset's model), or a natural or UUID primary key included in the form's fields. Models using the default BigAutoField primary key were not affected. . <https://www.djangoproject.com/weblog/2026/oct/06/security-releases/> . (Closes: #1150176) Checksums-Sha1: 8bcf535fc16ca93d55a314dc54bf3e978728c41e 2790 python-django_5.2.18-1.dsc fda911f9dbc830d570f8d77d2b4f5d037a6bbd88 10910238 python-django_5.2.18.orig.tar.gz 186ee8363b62fea416495d9d324472378af1e19f 43812 python-django_5.2.18-1.debian.tar.xz 27b3826035cb39cda84887de972187dd9916c759 7733 python-django_5.2.18-1_amd64.buildinfo Checksums-Sha256: bd737502bc5cf64596f297ff95d7a78a22ca88d670a704284069c53690bbfe55 2790 python-django_5.2.18-1.dsc 461c5dd06d2ea16bd5ca37d3f46e4def1d6b0fe7588c6f4e2119517bb0af8b2d 10910238 python-django_5.2.18.orig.tar.gz 487828267c704eaef45f7540d412b42a2bb502a24d2a7293bde450a031f8009a 43812 python-django_5.2.18-1.debian.tar.xz a0c948c00b4faab80820b8e5bcc8f7d40b5423dec78bc37fbd65bd1d72f08933 7733 python-django_5.2.18-1_amd64.buildinfo Files: 14b7e581a171ba864bcb37c3f19aa1e1 2790 python optional python-django_5.2.18-1.dsc 37d9504be21272595b91c2aa3ef4904c 10910238 python optional python-django_5.2.18.orig.tar.gz 3def77c7d6227d57f7687f586edc586a 43812 python optional python-django_5.2.18-1.debian.tar.xz 03ff0317aa2679ff480f2a36b4c642c5 7733 python optional python-django_5.2.18-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmrFFe8ACgkQHpU+J9Qx HljiNg//d6C354u9AVq7eKLdHMoQ+d5Vkt8rabqC1l9x4BGCX++/NerNgr5hPvIK tLuPftC1+lOixY92MmAdvgky49qXwk/lbO16/73pNOUibdYwNYAa7pWlXX1ym4Cp GN4a49KR61GnXF5UjOdmB+GWbBR9C8sAvQ86ut50AztqvHnHiQ5/FfDs1dpM+qIq ZA8CDj3yW1U8IswVhMrBCIfqz2+VCYybEuC6ojUbVd7Gw8FspxkxlZwkzNO81szG qys4Xtgi0vbiLviuvG9t5bncypn2ChT92j2/SyJ3lGuCVhtRb1A9ktdyKsQBB1kB uf+TdY9Snn1ZAvla6Q6wyMNUp5Ro9lZBg3N7tOHLTHhbbkkmmKPpOK5zoVvaWmCF nmsHqHrA4Z0wDzW04X5Bq/p2DyWbXm5ai0LU5WBQrD4wIlVbQiw8RVXyrHaAo+II joO4QaGpEeL3z9kaZsoiaRn2fHoSqVCsiTsZhL9eSpysM0LzllwOd+KS/cxCpkBW 8WFFuHFtgWOAXeqV132eLsQE37y42sKho7euKKycqubMZFByoL7n+WgV4JTF/J0a WtKCPV5PP/4xJwd5Ya5MX3974fL09JzeDEW3sELTCs9iXp6ox7Xeh0X0jIY4/p7T e/cnu740DZOfp+iLHQ4EHHcegp9nJCf38tvdI8MJZ35MmB3EaN8= =kbnO -----END PGP SIGNATURE-----