-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 06 Oct 2026 08:14:09 -0700 Source: python-django Built-For-Profiles: nocheck Architecture: source Version: 3:6.1.2-1 Distribution: experimental Urgency: high Maintainer: Debian Python Team <team+python@tracker.debian.org> Changed-By: Chris Lamb <lamby@debian.org> Closes: 1150176 Changes: python-django (3:6.1.2-1) experimental; urgency=high . * New upstream security release: . - CVE-2026-77050: Potential denial-of-service vulnerability in get_supported_language_variant. This method was subject to a potential denial-of-service attack when processing many distinct and very long language codes. Language codes were used as keys in an in-memory cache before their length was limited, potentially consuming excessive process memory. To mitigate this vulnerability, language codes longer than 500 characters are now rejected or truncated before the cached lookup. . - CVE-2026-84429: Potential denial-of-service vulnerability in HTTP header parsing. django.utils.http.parse_header_parameters() was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with many separators inside a quoted parameter. An unauthenticated request could reach this through common headers such as Accept or Content-Type, for instance via the content negotiation performed by HttpRequest.accepts(). The per-call length limit does not bound the combined size of repeated headers. The undocumented django.utils.http.parse_header_parameters() function now uses Python's email.message.Message for parsing. As a result, parsing of some malformed or unusual header values may differ, for example, RFC 2231 values with a missing encoding are now decoded. . - CVE-2026-87890: Potential request forgery via spatial lookup byte values. Spatial lookups accepted raster values provided as bytes without requiring them to be explicitly wrapped in django.contrib.gis.gdal's GDALRaster. Although these values were opened through GDAL's in-memory virtual filesystem, they could contain a VRT document referencing an external raster source. This could cause GDAL to issue network requests as the Django process user while preparing the lookup. This issue could be exploited by applications that passed attacker-controlled bytes directly to a spatial lookup. This was overlooked in the fix for CVE-2026-15307. To mitigate this issue, raster values provided as bytes must now be wrapped in GDALRaster before being used in spatial lookups. Byte values representing valid hexadecimal geometries remain accepted. This is a backward incompatible change. . - CVE-2026-87975: Prevent privilege abuse in model formsets with editable primary keys. Model formsets incorrectly allowed forged POST data to either delete instances outside the limiting queryset or create instances via edit-only formsets when the model's primary key could be set through the form, such as with a OneToOneField (or parent link used as the primary key of an inline formset's model), or a natural or UUID primary key included in the form's fields. Models using the default BigAutoField primary key were not affected. . <https://www.djangoproject.com/weblog/2026/oct/06/security-releases/> . (Closes: #1150176) Checksums-Sha1: 75c2db8fb311ec4e1ebc4c2875294e0651041758 2783 python-django_6.1.2-1.dsc 933b451da0f4f1605cbbad01e1a00f535b4a73a3 11251425 python-django_6.1.2.orig.tar.gz e69e47946c428054f4f34ed06b122ae2b8bfd080 34312 python-django_6.1.2-1.debian.tar.xz 4ff2ffa9d55f1f26cd6a70ee8b35278964bf1df6 7723 python-django_6.1.2-1_amd64.buildinfo Checksums-Sha256: 01082304b925eda9d165ea2cf7b16f5a1ff99cae7f5adabb30a526b4c5ab47d2 2783 python-django_6.1.2-1.dsc a1e92451ccb8b514e91bbb3b6d186d20b4030558f116b5d9de6535455ff210b7 11251425 python-django_6.1.2.orig.tar.gz 2e0818e96d0f5dbb54d17537350049630ed3cd680e8408aed680f6c45b134b1e 34312 python-django_6.1.2-1.debian.tar.xz 86a8935096f0188e1e569f00d2df9a41570a0d2a2e6e333b7f48863d5084ad2f 7723 python-django_6.1.2-1_amd64.buildinfo Files: 72a56685817867c3cf6c9961f0af5403 2783 python optional python-django_6.1.2-1.dsc 7c2461ccfcea3d11464ef207fa0bcbed 11251425 python optional python-django_6.1.2.orig.tar.gz d67b475d2e3e7f0140119456ee735171 34312 python optional python-django_6.1.2-1.debian.tar.xz b1046398fd664d95641fdcf82296da43 7723 python optional python-django_6.1.2-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmrFE7AACgkQHpU+J9Qx HlheLhAAjmhigfsQh7uhSFUaeO8Z6uEH2AehbG3WgGWOyy9NyY6cnhEPdUHvdKou qPM4uxrerZpbRVg2LvEJWit3B1NkN4B4CRcuEG/fkzFDXoj5otlpKsJlLFVEgUlb 64oJJ56vtSKqrm6J1fJHwO10sfTc3EYOvDsxJdPM0U9locO15ziXbflCw9My/BwT gZ8Gtr6aYeE+sJ9DkS8KXJ1iFEHIxetBk9aAzf/qkjpJkgJGAw7+Grnhd9KhgP+g vHFPv0tFPcrvtVXNkhyPPgVUMYxRIVVLTOmzUPyxkY8mEodUyQmbmoQ3iyS5KFAq U14ft+ALnWdGiaeFLWlBx0KGbOAaLle5gmywmgRFxRq1g4P+48OiuPhFnzrgqQDp 7/4iAS/BH0L/3ChxD9RRRxMrueRYqwAdZLZznJibHadRLmAWYqlS2OLZGZBZ6WB8 GoYTfzZf6wTaVniDVHl569g5sr6ohNE41TzZyb7LlWz/l/F0J+DQP0KEkPWMxGNa bPYLDMozw97IAVvBFobS1ri8tWCoZJ2l9GFJeC6NyTD0ZdIwyqRe2dDr42VTLDKe UVLUi56Z4ldvzJlc79muBjv6YV7AnW4vHHMDN0fsYMd/UjCZv8xbR4JZ9pyqHTDk NKfD3tuhehJN8s5m8nkV1Nzi6ulcAR8bfdh83JkU5nZurvLasYY= =ESwJ -----END PGP SIGNATURE-----