- Package:
- python-django
- Source:
- python-django
- Submitter:
- Chris Lamb
- Date:
- 2026-10-06 18:51:08 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for python-django: * CVE-2026-77050: Potential denial-of-service vulnerability in get_supported_language_variant(). django.utils.translation.get_supported_language_variant() was subject to a potential denial-of-service attack when processing many distinct, very long language codes. Language codes were used as keys in an in-memory cache before their length was limited, potentially consuming excessive process memory. [0] * CVE-2026-84429: Potential denial-of-service vulnerability in HTTP header parsing. django.utils.http.parse_header_parameters() was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with many separators inside a quoted parameter. An unauthenticated request could reach this parsing through headers such as Accept or Content-Type, for instance via the content negotiation performed by HttpRequest.accepts(). The per-call length limit does not bound the combined size of repeated headers. The undocumented django.utils.http.parse_header_parameters() function now uses Python's email.message.Message for parsing. As a result, parsing of some malformed or unusual header values may differ, for example, RFC 2231 values with a missing encoding are now decoded. [1] * CVE-2026-87890: Potential request forgery via spatial lookup byte values. Spatial lookups accepted raster values provided as bytes without requiring them to be explicitly wrapped in django.contrib.gis.gdal.GDALRaster. Although these values were opened through GDAL's in-memory virtual filesystem, they could contain a VRT document referencing an external raster source. This could cause GDAL to issue network requests as the Django process user while preparing the lookup. This issue could be exploited by applications that passed attacker-controlled bytes directly to a spatial lookup. It was overlooked in the fix for CVE-2026-15307. To mitigate this issue, raster values provided as bytes must now be wrapped in GDALRaster before being used in spatial lookups. Byte values representing valid hexadecimal geometries remain accepted. [2] * CVE-2026-87975: Privilege abuse in model formsets with editable primary keys. Model formsets incorrectly allowed forged POST data to either delete instances outside the limiting queryset or create instances via edit-only formsets when the model's primary key could be set through the form, such as with: a OneToOneField (or parent link used as the primary key of an inline formset's model), or a natural or UUID primary key included in the form's fields. Models using the default BigAutoField primary key were not affected. [3] For further information see upstream's blog post [4], as well as: [0] https://security-tracker.debian.org/tracker/CVE-2026-77050 https://www.cve.org/CVERecord?id=CVE-2026-77050 [1] https://security-tracker.debian.org/tracker/CVE-2026-84429 https://www.cve.org/CVERecord?id=CVE-2026-84429 [2] https://security-tracker.debian.org/tracker/CVE-2026-87890 https://www.cve.org/CVERecord?id=CVE-2026-87890 [3] https://security-tracker.debian.org/tracker/CVE-2026-87975 https://www.cve.org/CVERecord?id=CVE-2026-87975 [4] https://www.djangoproject.com/weblog/2026/oct/06/security-releases/ Regards,
We believe that the bug you reported is fixed in the latest version of
python-django, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1150176@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Chris Lamb <lamby@debian.org> (supplier of updated python-django package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 06 Oct 2026 08:36:10 -0700
Source: python-django
Built-For-Profiles: nocheck
Architecture: source
Version: 3:5.2.18-1
Distribution: unstable
Urgency: high
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Chris Lamb <lamby@debian.org>
Closes: 1150176
Changes:
python-django (3:5.2.18-1) unstable; urgency=high
.
* New upstream security release:
.
- CVE-2026-77050: Potential denial-of-service vulnerability in
get_supported_language_variant. This method was subject to a potential
denial-of-service attack when processing many distinct and very long
language codes. Language codes were used as keys in an in-memory cache
before their length was limited, potentially consuming excessive process
memory. To mitigate this vulnerability, language codes longer than 500
characters are now rejected or truncated before the cached lookup.
.
- CVE-2026-84429: Potential denial-of-service vulnerability in HTTP header
parsing. django.utils.http.parse_header_parameters() was subject to a
potential denial-of-service attack due to quadratic time complexity when
parsing a value with many separators inside a quoted parameter. An
unauthenticated request could reach this through common headers such as
Accept or Content-Type, for instance via the content negotiation
performed by HttpRequest.accepts(). The per-call length limit does not
bound the combined size of repeated headers. The undocumented
django.utils.http.parse_header_parameters() function now uses Python's
email.message.Message for parsing. As a result, parsing of some malformed
or unusual header values may differ, for example, RFC 2231 values with a
missing encoding are now decoded.
.
- CVE-2026-87890: Potential request forgery via spatial lookup byte values.
Spatial lookups accepted raster values provided as bytes without
requiring them to be explicitly wrapped in django.contrib.gis.gdal's
GDALRaster. Although these values were opened through GDAL's in-memory
virtual filesystem, they could contain a VRT document referencing an
external raster source. This could cause GDAL to issue network requests
as the Django process user while preparing the lookup. This issue could
be exploited by applications that passed attacker-controlled bytes
directly to a spatial lookup. This was overlooked in the fix for
CVE-2026-15307. To mitigate this issue, raster values provided as bytes
must now be wrapped in GDALRaster before being used in spatial lookups.
Byte values representing valid hexadecimal geometries remain accepted.
This is a backward incompatible change.
.
- CVE-2026-87975: Prevent privilege abuse in model formsets with editable
primary keys. Model formsets incorrectly allowed forged POST data to
either delete instances outside the limiting queryset or create instances
via edit-only formsets when the model's primary key could be set through
the form, such as with a OneToOneField (or parent link used as the
primary key of an inline formset's model), or a natural or UUID primary
key included in the form's fields. Models using the default BigAutoField
primary key were not affected.
.
<https://www.djangoproject.com/weblog/2026/oct/06/security-releases/>
.
(Closes: #1150176)
Checksums-Sha1:
8bcf535fc16ca93d55a314dc54bf3e978728c41e 2790 python-django_5.2.18-1.dsc
fda911f9dbc830d570f8d77d2b4f5d037a6bbd88 10910238 python-django_5.2.18.orig.tar.gz
186ee8363b62fea416495d9d324472378af1e19f 43812 python-django_5.2.18-1.debian.tar.xz
27b3826035cb39cda84887de972187dd9916c759 7733 python-django_5.2.18-1_amd64.buildinfo
Checksums-Sha256:
bd737502bc5cf64596f297ff95d7a78a22ca88d670a704284069c53690bbfe55 2790 python-django_5.2.18-1.dsc
461c5dd06d2ea16bd5ca37d3f46e4def1d6b0fe7588c6f4e2119517bb0af8b2d 10910238 python-django_5.2.18.orig.tar.gz
487828267c704eaef45f7540d412b42a2bb502a24d2a7293bde450a031f8009a 43812 python-django_5.2.18-1.debian.tar.xz
a0c948c00b4faab80820b8e5bcc8f7d40b5423dec78bc37fbd65bd1d72f08933 7733 python-django_5.2.18-1_amd64.buildinfo
Files:
14b7e581a171ba864bcb37c3f19aa1e1 2790 python optional python-django_5.2.18-1.dsc
37d9504be21272595b91c2aa3ef4904c 10910238 python optional python-django_5.2.18.orig.tar.gz
3def77c7d6227d57f7687f586edc586a 43812 python optional python-django_5.2.18-1.debian.tar.xz
03ff0317aa2679ff480f2a36b4c642c5 7733 python optional python-django_5.2.18-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmrFFe8ACgkQHpU+J9Qx
HljiNg//d6C354u9AVq7eKLdHMoQ+d5Vkt8rabqC1l9x4BGCX++/NerNgr5hPvIK
tLuPftC1+lOixY92MmAdvgky49qXwk/lbO16/73pNOUibdYwNYAa7pWlXX1ym4Cp
GN4a49KR61GnXF5UjOdmB+GWbBR9C8sAvQ86ut50AztqvHnHiQ5/FfDs1dpM+qIq
ZA8CDj3yW1U8IswVhMrBCIfqz2+VCYybEuC6ojUbVd7Gw8FspxkxlZwkzNO81szG
qys4Xtgi0vbiLviuvG9t5bncypn2ChT92j2/SyJ3lGuCVhtRb1A9ktdyKsQBB1kB
uf+TdY9Snn1ZAvla6Q6wyMNUp5Ro9lZBg3N7tOHLTHhbbkkmmKPpOK5zoVvaWmCF
nmsHqHrA4Z0wDzW04X5Bq/p2DyWbXm5ai0LU5WBQrD4wIlVbQiw8RVXyrHaAo+II
joO4QaGpEeL3z9kaZsoiaRn2fHoSqVCsiTsZhL9eSpysM0LzllwOd+KS/cxCpkBW
8WFFuHFtgWOAXeqV132eLsQE37y42sKho7euKKycqubMZFByoL7n+WgV4JTF/J0a
WtKCPV5PP/4xJwd5Ya5MX3974fL09JzeDEW3sELTCs9iXp6ox7Xeh0X0jIY4/p7T
e/cnu740DZOfp+iLHQ4EHHcegp9nJCf38tvdI8MJZ35MmB3EaN8=
=kbnO
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
python-django, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1150176@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Chris Lamb <lamby@debian.org> (supplier of updated python-django package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 06 Oct 2026 08:14:09 -0700
Source: python-django
Built-For-Profiles: nocheck
Architecture: source
Version: 3:6.1.2-1
Distribution: experimental
Urgency: high
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Chris Lamb <lamby@debian.org>
Closes: 1150176
Changes:
python-django (3:6.1.2-1) experimental; urgency=high
.
* New upstream security release:
.
- CVE-2026-77050: Potential denial-of-service vulnerability in
get_supported_language_variant. This method was subject to a potential
denial-of-service attack when processing many distinct and very long
language codes. Language codes were used as keys in an in-memory cache
before their length was limited, potentially consuming excessive process
memory. To mitigate this vulnerability, language codes longer than 500
characters are now rejected or truncated before the cached lookup.
.
- CVE-2026-84429: Potential denial-of-service vulnerability in HTTP header
parsing. django.utils.http.parse_header_parameters() was subject to a
potential denial-of-service attack due to quadratic time complexity when
parsing a value with many separators inside a quoted parameter. An
unauthenticated request could reach this through common headers such as
Accept or Content-Type, for instance via the content negotiation
performed by HttpRequest.accepts(). The per-call length limit does not
bound the combined size of repeated headers. The undocumented
django.utils.http.parse_header_parameters() function now uses Python's
email.message.Message for parsing. As a result, parsing of some malformed
or unusual header values may differ, for example, RFC 2231 values with a
missing encoding are now decoded.
.
- CVE-2026-87890: Potential request forgery via spatial lookup byte values.
Spatial lookups accepted raster values provided as bytes without
requiring them to be explicitly wrapped in django.contrib.gis.gdal's
GDALRaster. Although these values were opened through GDAL's in-memory
virtual filesystem, they could contain a VRT document referencing an
external raster source. This could cause GDAL to issue network requests
as the Django process user while preparing the lookup. This issue could
be exploited by applications that passed attacker-controlled bytes
directly to a spatial lookup. This was overlooked in the fix for
CVE-2026-15307. To mitigate this issue, raster values provided as bytes
must now be wrapped in GDALRaster before being used in spatial lookups.
Byte values representing valid hexadecimal geometries remain accepted.
This is a backward incompatible change.
.
- CVE-2026-87975: Prevent privilege abuse in model formsets with editable
primary keys. Model formsets incorrectly allowed forged POST data to
either delete instances outside the limiting queryset or create instances
via edit-only formsets when the model's primary key could be set through
the form, such as with a OneToOneField (or parent link used as the
primary key of an inline formset's model), or a natural or UUID primary
key included in the form's fields. Models using the default BigAutoField
primary key were not affected.
.
<https://www.djangoproject.com/weblog/2026/oct/06/security-releases/>
.
(Closes: #1150176)
Checksums-Sha1:
75c2db8fb311ec4e1ebc4c2875294e0651041758 2783 python-django_6.1.2-1.dsc
933b451da0f4f1605cbbad01e1a00f535b4a73a3 11251425 python-django_6.1.2.orig.tar.gz
e69e47946c428054f4f34ed06b122ae2b8bfd080 34312 python-django_6.1.2-1.debian.tar.xz
4ff2ffa9d55f1f26cd6a70ee8b35278964bf1df6 7723 python-django_6.1.2-1_amd64.buildinfo
Checksums-Sha256:
01082304b925eda9d165ea2cf7b16f5a1ff99cae7f5adabb30a526b4c5ab47d2 2783 python-django_6.1.2-1.dsc
a1e92451ccb8b514e91bbb3b6d186d20b4030558f116b5d9de6535455ff210b7 11251425 python-django_6.1.2.orig.tar.gz
2e0818e96d0f5dbb54d17537350049630ed3cd680e8408aed680f6c45b134b1e 34312 python-django_6.1.2-1.debian.tar.xz
86a8935096f0188e1e569f00d2df9a41570a0d2a2e6e333b7f48863d5084ad2f 7723 python-django_6.1.2-1_amd64.buildinfo
Files:
72a56685817867c3cf6c9961f0af5403 2783 python optional python-django_6.1.2-1.dsc
7c2461ccfcea3d11464ef207fa0bcbed 11251425 python optional python-django_6.1.2.orig.tar.gz
d67b475d2e3e7f0140119456ee735171 34312 python optional python-django_6.1.2-1.debian.tar.xz
b1046398fd664d95641fdcf82296da43 7723 python optional python-django_6.1.2-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmrFE7AACgkQHpU+J9Qx
HlheLhAAjmhigfsQh7uhSFUaeO8Z6uEH2AehbG3WgGWOyy9NyY6cnhEPdUHvdKou
qPM4uxrerZpbRVg2LvEJWit3B1NkN4B4CRcuEG/fkzFDXoj5otlpKsJlLFVEgUlb
64oJJ56vtSKqrm6J1fJHwO10sfTc3EYOvDsxJdPM0U9locO15ziXbflCw9My/BwT
gZ8Gtr6aYeE+sJ9DkS8KXJ1iFEHIxetBk9aAzf/qkjpJkgJGAw7+Grnhd9KhgP+g
vHFPv0tFPcrvtVXNkhyPPgVUMYxRIVVLTOmzUPyxkY8mEodUyQmbmoQ3iyS5KFAq
U14ft+ALnWdGiaeFLWlBx0KGbOAaLle5gmywmgRFxRq1g4P+48OiuPhFnzrgqQDp
7/4iAS/BH0L/3ChxD9RRRxMrueRYqwAdZLZznJibHadRLmAWYqlS2OLZGZBZ6WB8
GoYTfzZf6wTaVniDVHl569g5sr6ohNE41TzZyb7LlWz/l/F0J+DQP0KEkPWMxGNa
bPYLDMozw97IAVvBFobS1ri8tWCoZJ2l9GFJeC6NyTD0ZdIwyqRe2dDr42VTLDKe
UVLUi56Z4ldvzJlc79muBjv6YV7AnW4vHHMDN0fsYMd/UjCZv8xbR4JZ9pyqHTDk
NKfD3tuhehJN8s5m8nkV1Nzi6ulcAR8bfdh83JkU5nZurvLasYY=
=ESwJ
-----END PGP SIGNATURE-----