[ubuntu/resolute-updates] python-django 3:5.2.9-0ubuntu4.3 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Thu Oct 1 07:02:52 UTC 2026
python-django (3:5.2.9-0ubuntu4.3) resolute-security; urgency=medium
* SECURITY UPDATE: Server-side file write and request forgery via spatial
lookups
- debian/patches/CVE-2026-15307.patch: blocked raster strings and dicts
in spatial lookups. in
django/contrib/gis/db/models/fields.py,
django/contrib/gis/gdal/raster/source.py,
docs/ref/contrib/gis/db-api.txt,
docs/ref/contrib/gis/gdal.txt, tests/gis_tests/geoadmin/tests.py,
tests/gis_tests/geoapp/tests.py,
tests/gis_tests/rasterapp/test_rasterfield.py,
tests/gis_tests/test_geoforms.py.
- CVE-2026-15307
* SECURITY UPDATE: Potential exposure of private data via case-sensitive
Cache-Control directives in UpdateCacheMiddleware
- debian/patches/CVE-2026-8404.patch: use Cache-Control directives
case-insensitively in UpdateCacheMiddleware. in
django/middleware/cache.py, tests/cache/tests.py.
- CVE-2026-8404
Date: 2026-09-29 07:58:29.725136+00:00
Changed-By: Hurman <hurman at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/python-django/3:5.2.9-0ubuntu4.3
-------------- next part --------------
Sorry, changesfile not available.
More information about the Resolute-changes
mailing list