-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4736-1 [email protected]
https://www.debian.org/lts/security/ Chris Lamb
August 12, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : python-django
Version : 2:2.2.28-1~deb11u13 3:3.2.25-0+deb12u4
CVE ID : CVE-2026-15337 CVE-2026-15920
Two issues were discovered in Django, the Python-based web
development framework.
CVE-2026-15337
Avoid a potential denial-of-service vulnerability in the
check_for_language() method in the django.utils.translation
module.
This method was subject to a potential denial-of-service (DoS)
attack when checking many distinct, very long language codes. To
mitigate this vulnerability, language codes longer than 500
characters are now rejected before the cached lookup.
CVE-2026-15920
Prevent a potential cross-site scripting (XSS) attack via
bogus URLField values in the Django admin.
The admin renders URLField values as clickable links on
'changelist' views and read-only fields. This link was hitherto
generated without validating the value as a safe URL, so a stored
value using a potentially dangerous scheme was rendered as a
link. URLField values shown via display_for_field are now
validated using the URLValidator class before a link is rendered
and displayed as plain text if validation fails.
For Debian 11 bullseye, these problems have been fixed in version
2:2.2.28-1~deb11u13.
For Debian 12 bookworm, these problems have been fixed in version
3:3.2.25-0+deb12u4.
We recommend that you upgrade your python-django packages.
For the detailed security status of python-django please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/python-django
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmp8yOgACgkQHpU+J9Qx
Hlgiew//SD70HHlC1ac3lEa8wymdoPV45BpoFNy0aD7ba43DWJfs8FUnREfD83CO
TCASn/UqJv/AEbBT6fUK+K6UP0sWUMiW9ilbo+z5i/Wbz+ymHU7QB7ZZ3l/hScg1
ClOdB6MEP1IXpYM0mM3JOW15W0bnkDcgPww+JfKXIM0NkrdmpQFIgol/dcP8QvSe
KTRK0/h3tq0jfTo5zd7TLBX1I45Ny8Y/7lYG7YEo5nY3Z/hfNrA3sBybMFxeieQi
H11vm75YADuztO1XV4zXVo2z2dnOGygjczx1BQuUvCcxCYBo+cfD942VSjaZoZyp
xzgstL2fMPiafVhnIJQONvRBe6LqghYmILDsiHd6UDw1kV7dAbqCTq8b21vayjl7
pUkqvKh2VejwA+ddiYqUE19D6GVOw83I0/5h+NyPbbLCxeroUmUYMagk1Y81x5L7
9g9GAEFRQoLqmrhH5yQ9U0uqpQatD1Jj24bF+T388HU3dPhgHJQF0vD8vui8VIKM
Nxqo22TgVop0aRERh2WysP3uwMfTqaaU11vMiXgJKcsCkWXo9xXbxNXgtX4tMjAy
bZ1b8pKNvfQtFQM7AzFnBRq1RIXms6hQ7T7QVWWkIpbjNM40t+9IvTS8qi34a/ur
rQq70f5DPdSRXZlyGP4VmFNQDAMYy/SyqFPkDWdqg6m9QKBe4OY=
=KauC
-----END PGP SIGNATURE-----