[ubuntu/resolute-proposed] python-django 3:5.2.9-0ubuntu4 (Accepted)
Marc Deslauriers
marc.deslauriers at ubuntu.com
Tue Apr 7 20:05:31 UTC 2026
python-django (3:5.2.9-0ubuntu4) resolute; urgency=medium
* SECURITY UPDATE: Potential denial-of-service vulnerability in
MultiPartParser via base64-encoded file upload
- debian/patches/CVE-2026-33033.patch: mitigate potential DoS in
MultiPartParser in django/http/multipartparser.py,
tests/requests_tests/tests.py.
- CVE-2026-33033
* SECURITY UPDATE: Potential denial-of-service vulnerability in ASGI
requests via memory upload limit bypass
- debian/patches/CVE-2026-33034.patch: enforce
DATA_UPLOAD_MAX_MEMORY_SIZE on body size in ASGI requests in
django/http/request.py, tests/asgi/tests.py.
- CVE-2026-33034
* SECURITY UPDATE: ASGI header spoofing via underscore/hyphen conflation
- debian/patches/CVE-2026-3902.patch: ignore headers with underscores
in ASGIRequest in django/core/handlers/asgi.py,
django/test/client.py, tests/asgi/tests.py.
- CVE-2026-3902
* SECURITY UPDATE: Privilege abuse in GenericInlineModelAdmin
- debian/patches/CVE-2026-4277.patch: Check add permissions in
GenericInlineModelAdmin in django/contrib/contenttypes/admin.py,
tests/generic_inline_admin/tests.py.
- CVE-2026-4277
* SECURITY UPDATE: Privilege abuse in ModelAdmin.list_editable
- debian/patches/CVE-2026-4292.patch: Disallow instance creation via
ModelAdmin.list_editable in django/contrib/admin/options.py,
tests/admin_views/admin.py, tests/admin_views/tests.py.
- CVE-2026-4292
Date: Wed, 01 Apr 2026 09:17:54 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/python-django/3:5.2.9-0ubuntu4
-------------- next part --------------
Format: 1.8
Date: Wed, 01 Apr 2026 09:17:54 -0400
Source: python-django
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 3:5.2.9-0ubuntu4
Distribution: resolute
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Changes:
python-django (3:5.2.9-0ubuntu4) resolute; urgency=medium
.
* SECURITY UPDATE: Potential denial-of-service vulnerability in
MultiPartParser via base64-encoded file upload
- debian/patches/CVE-2026-33033.patch: mitigate potential DoS in
MultiPartParser in django/http/multipartparser.py,
tests/requests_tests/tests.py.
- CVE-2026-33033
* SECURITY UPDATE: Potential denial-of-service vulnerability in ASGI
requests via memory upload limit bypass
- debian/patches/CVE-2026-33034.patch: enforce
DATA_UPLOAD_MAX_MEMORY_SIZE on body size in ASGI requests in
django/http/request.py, tests/asgi/tests.py.
- CVE-2026-33034
* SECURITY UPDATE: ASGI header spoofing via underscore/hyphen conflation
- debian/patches/CVE-2026-3902.patch: ignore headers with underscores
in ASGIRequest in django/core/handlers/asgi.py,
django/test/client.py, tests/asgi/tests.py.
- CVE-2026-3902
* SECURITY UPDATE: Privilege abuse in GenericInlineModelAdmin
- debian/patches/CVE-2026-4277.patch: Check add permissions in
GenericInlineModelAdmin in django/contrib/contenttypes/admin.py,
tests/generic_inline_admin/tests.py.
- CVE-2026-4277
* SECURITY UPDATE: Privilege abuse in ModelAdmin.list_editable
- debian/patches/CVE-2026-4292.patch: Disallow instance creation via
ModelAdmin.list_editable in django/contrib/admin/options.py,
tests/admin_views/admin.py, tests/admin_views/tests.py.
- CVE-2026-4292
Checksums-Sha1:
78feabe8db2b5a9289a06fa53906da019a85f2b1 2890 python-django_5.2.9-0ubuntu4.dsc
b126b287b77fc1bbb1cfddbd190c014507d36f31 49864 python-django_5.2.9-0ubuntu4.debian.tar.xz
47d3abdc163bd44d375e969edfadd2a24afb688b 17676 python-django_5.2.9-0ubuntu4_source.buildinfo
Checksums-Sha256:
972317c5f4f8773fe8ef11d5c3095668faab6be26b19d5d31cc45e29da1bc072 2890 python-django_5.2.9-0ubuntu4.dsc
789c2fef2bb492bbcb65e6c854e29ffecdacfa11e0435b05d66f94af643c3566 49864 python-django_5.2.9-0ubuntu4.debian.tar.xz
4fadf176fdbc9b38088553da6aecad89815ecf063672abea626f1825df3be55e 17676 python-django_5.2.9-0ubuntu4_source.buildinfo
Files:
5e129728f770d2c8f632dd48d413da9f 2890 python optional python-django_5.2.9-0ubuntu4.dsc
725e05e34476585e274023b8a62e482a 49864 python optional python-django_5.2.9-0ubuntu4.debian.tar.xz
f6a197640627bb360508d26cf59b15a5 17676 python optional python-django_5.2.9-0ubuntu4_source.buildinfo
Original-Maintainer: Debian Python Team <team+python at tracker.debian.org>
More information about the Resolute-changes
mailing list