[ubuntu/questing-security] python-django 3:5.2.4-1ubuntu2.2 (Accepted)

Hlib Korzhynskyy hlib.korzhynskyy at canonical.com
Tue Dec 2 14:57:39 UTC 2025


python-django (3:5.2.4-1ubuntu2.2) questing-security; urgency=medium

  * SECURITY UPDATE: SQL injection in FilteredRelation column aliases on
    PostgreSQL
    - debian/patches/CVE-2025-13372.patch: protect FilteredRelation against
      SQL injection in column aliases in
      django/db/backends/postgresql/compiler.py,
      tests/annotations/tests.py.
    - CVE-2025-13372
  * SECURITY UPDATE: DoS vulnerability in XML serializer text extraction
    - debian/patches/CVE-2025-64460.patch: corrected quadratic inner text
      accumulation in XML serializer in
      django/core/serializers/xml_serializer.py,
      docs/topics/serialization.txt,
      tests/serializers/test_deserialization.py.
    - CVE-2025-64460

Date: 2025-11-26 17:19:11.943798+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
https://launchpad.net/ubuntu/+source/python-django/3:5.2.4-1ubuntu2.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Questing-changes mailing list