-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4736-1                [email protected]
https://www.debian.org/lts/security/                           Chris Lamb
August 12, 2026                               https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : python-django
Version        : 2:2.2.28-1~deb11u13 3:3.2.25-0+deb12u4
CVE ID         : CVE-2026-15337 CVE-2026-15920

Two issues were discovered in Django, the Python-based web
development framework.

CVE-2026-15337

    Avoid a potential denial-of-service vulnerability in the
    check_for_language() method in the django.utils.translation
    module.

    This method was subject to a potential denial-of-service (DoS)
    attack when checking many distinct, very long language codes. To
    mitigate this vulnerability, language codes longer than 500
    characters are now rejected before the cached lookup.

CVE-2026-15920

    Prevent a potential cross-site scripting (XSS) attack via
    bogus URLField values in the Django admin.

    The admin renders URLField values as clickable links on
    'changelist' views and read-only fields. This link was hitherto
    generated without validating the value as a safe URL, so a stored
    value using a potentially dangerous scheme was rendered as a
    link. URLField values shown via display_for_field are now
    validated using the URLValidator class before a link is rendered
    and displayed as plain text if validation fails.

For Debian 11 bullseye, these problems have been fixed in version
2:2.2.28-1~deb11u13.

For Debian 12 bookworm, these problems have been fixed in version
3:3.2.25-0+deb12u4.

We recommend that you upgrade your python-django packages.

For the detailed security status of python-django please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/python-django

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmp8yOgACgkQHpU+J9Qx
Hlgiew//SD70HHlC1ac3lEa8wymdoPV45BpoFNy0aD7ba43DWJfs8FUnREfD83CO
TCASn/UqJv/AEbBT6fUK+K6UP0sWUMiW9ilbo+z5i/Wbz+ymHU7QB7ZZ3l/hScg1
ClOdB6MEP1IXpYM0mM3JOW15W0bnkDcgPww+JfKXIM0NkrdmpQFIgol/dcP8QvSe
KTRK0/h3tq0jfTo5zd7TLBX1I45Ny8Y/7lYG7YEo5nY3Z/hfNrA3sBybMFxeieQi
H11vm75YADuztO1XV4zXVo2z2dnOGygjczx1BQuUvCcxCYBo+cfD942VSjaZoZyp
xzgstL2fMPiafVhnIJQONvRBe6LqghYmILDsiHd6UDw1kV7dAbqCTq8b21vayjl7
pUkqvKh2VejwA+ddiYqUE19D6GVOw83I0/5h+NyPbbLCxeroUmUYMagk1Y81x5L7
9g9GAEFRQoLqmrhH5yQ9U0uqpQatD1Jj24bF+T388HU3dPhgHJQF0vD8vui8VIKM
Nxqo22TgVop0aRERh2WysP3uwMfTqaaU11vMiXgJKcsCkWXo9xXbxNXgtX4tMjAy
bZ1b8pKNvfQtFQM7AzFnBRq1RIXms6hQ7T7QVWWkIpbjNM40t+9IvTS8qi34a/ur
rQq70f5DPdSRXZlyGP4VmFNQDAMYy/SyqFPkDWdqg6m9QKBe4OY=
=KauC
-----END PGP SIGNATURE-----

Reply via email to