[ubuntu/resolute-updates] python-django 3:5.2.9-0ubuntu4.3 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Thu Oct 1 07:02:52 UTC 2026


python-django (3:5.2.9-0ubuntu4.3) resolute-security; urgency=medium

  * SECURITY UPDATE: Server-side file write and request forgery via spatial
    lookups
    - debian/patches/CVE-2026-15307.patch: blocked raster strings and dicts
      in spatial lookups. in
      django/contrib/gis/db/models/fields.py,
      django/contrib/gis/gdal/raster/source.py, 
      docs/ref/contrib/gis/db-api.txt,
      docs/ref/contrib/gis/gdal.txt, tests/gis_tests/geoadmin/tests.py,
      tests/gis_tests/geoapp/tests.py,
      tests/gis_tests/rasterapp/test_rasterfield.py,
      tests/gis_tests/test_geoforms.py.
    - CVE-2026-15307
  * SECURITY UPDATE: Potential exposure of private data via case-sensitive
    Cache-Control directives in UpdateCacheMiddleware
    - debian/patches/CVE-2026-8404.patch: use Cache-Control directives 
      case-insensitively in UpdateCacheMiddleware. in
      django/middleware/cache.py, tests/cache/tests.py.
    - CVE-2026-8404

Date: 2026-09-29 07:58:29.725136+00:00
Changed-By: Hurman <hurman at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/python-django/3:5.2.9-0ubuntu4.3
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list