[ubuntu/resolute-proposed] python-django 3:5.2.9-0ubuntu4 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Tue Apr 7 20:05:31 UTC 2026


python-django (3:5.2.9-0ubuntu4) resolute; urgency=medium

  * SECURITY UPDATE: Potential denial-of-service vulnerability in
    MultiPartParser via base64-encoded file upload
    - debian/patches/CVE-2026-33033.patch: mitigate potential DoS in
      MultiPartParser in django/http/multipartparser.py,
      tests/requests_tests/tests.py.
    - CVE-2026-33033
  * SECURITY UPDATE: Potential denial-of-service vulnerability in ASGI
    requests via memory upload limit bypass
    - debian/patches/CVE-2026-33034.patch: enforce
      DATA_UPLOAD_MAX_MEMORY_SIZE on body size in ASGI requests in
      django/http/request.py, tests/asgi/tests.py.
    - CVE-2026-33034
  * SECURITY UPDATE: ASGI header spoofing via underscore/hyphen conflation
    - debian/patches/CVE-2026-3902.patch: ignore headers with underscores
      in ASGIRequest in django/core/handlers/asgi.py,
      django/test/client.py, tests/asgi/tests.py.
    - CVE-2026-3902
  * SECURITY UPDATE: Privilege abuse in GenericInlineModelAdmin
    - debian/patches/CVE-2026-4277.patch: Check add permissions in
      GenericInlineModelAdmin in django/contrib/contenttypes/admin.py,
      tests/generic_inline_admin/tests.py.
    - CVE-2026-4277
  * SECURITY UPDATE: Privilege abuse in ModelAdmin.list_editable
    - debian/patches/CVE-2026-4292.patch: Disallow instance creation via
      ModelAdmin.list_editable in django/contrib/admin/options.py,
      tests/admin_views/admin.py, tests/admin_views/tests.py.
    - CVE-2026-4292

Date: Wed, 01 Apr 2026 09:17:54 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/python-django/3:5.2.9-0ubuntu4
-------------- next part --------------
Format: 1.8
Date: Wed, 01 Apr 2026 09:17:54 -0400
Source: python-django
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 3:5.2.9-0ubuntu4
Distribution: resolute
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Changes:
 python-django (3:5.2.9-0ubuntu4) resolute; urgency=medium
 .
   * SECURITY UPDATE: Potential denial-of-service vulnerability in
     MultiPartParser via base64-encoded file upload
     - debian/patches/CVE-2026-33033.patch: mitigate potential DoS in
       MultiPartParser in django/http/multipartparser.py,
       tests/requests_tests/tests.py.
     - CVE-2026-33033
   * SECURITY UPDATE: Potential denial-of-service vulnerability in ASGI
     requests via memory upload limit bypass
     - debian/patches/CVE-2026-33034.patch: enforce
       DATA_UPLOAD_MAX_MEMORY_SIZE on body size in ASGI requests in
       django/http/request.py, tests/asgi/tests.py.
     - CVE-2026-33034
   * SECURITY UPDATE: ASGI header spoofing via underscore/hyphen conflation
     - debian/patches/CVE-2026-3902.patch: ignore headers with underscores
       in ASGIRequest in django/core/handlers/asgi.py,
       django/test/client.py, tests/asgi/tests.py.
     - CVE-2026-3902
   * SECURITY UPDATE: Privilege abuse in GenericInlineModelAdmin
     - debian/patches/CVE-2026-4277.patch: Check add permissions in
       GenericInlineModelAdmin in django/contrib/contenttypes/admin.py,
       tests/generic_inline_admin/tests.py.
     - CVE-2026-4277
   * SECURITY UPDATE: Privilege abuse in ModelAdmin.list_editable
     - debian/patches/CVE-2026-4292.patch: Disallow instance creation via
       ModelAdmin.list_editable in django/contrib/admin/options.py,
       tests/admin_views/admin.py, tests/admin_views/tests.py.
     - CVE-2026-4292
Checksums-Sha1:
 78feabe8db2b5a9289a06fa53906da019a85f2b1 2890 python-django_5.2.9-0ubuntu4.dsc
 b126b287b77fc1bbb1cfddbd190c014507d36f31 49864 python-django_5.2.9-0ubuntu4.debian.tar.xz
 47d3abdc163bd44d375e969edfadd2a24afb688b 17676 python-django_5.2.9-0ubuntu4_source.buildinfo
Checksums-Sha256:
 972317c5f4f8773fe8ef11d5c3095668faab6be26b19d5d31cc45e29da1bc072 2890 python-django_5.2.9-0ubuntu4.dsc
 789c2fef2bb492bbcb65e6c854e29ffecdacfa11e0435b05d66f94af643c3566 49864 python-django_5.2.9-0ubuntu4.debian.tar.xz
 4fadf176fdbc9b38088553da6aecad89815ecf063672abea626f1825df3be55e 17676 python-django_5.2.9-0ubuntu4_source.buildinfo
Files:
 5e129728f770d2c8f632dd48d413da9f 2890 python optional python-django_5.2.9-0ubuntu4.dsc
 725e05e34476585e274023b8a62e482a 49864 python optional python-django_5.2.9-0ubuntu4.debian.tar.xz
 f6a197640627bb360508d26cf59b15a5 17676 python optional python-django_5.2.9-0ubuntu4_source.buildinfo
Original-Maintainer: Debian Python Team <team+python at tracker.debian.org>


More information about the Resolute-changes mailing list