Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian 11: DLA-4210-1 high: python-django update mitigates several risks

debian lts
Calendar Grey June 9, 2025
Dist Debian Esm H88
Updating the python-django package is vital for reinforcing your Debian system's security against vulnerabilities and protecting your application from threats
A number of vulnerabilities were discovered in Django, a popular Python-based web-development framework: * CVE-2025-48432: Potential log injection via unescaped request path

Summary

* CVE-2025-48432: Potential log injection via unescaped request path.

Django's internal HTTP response logging used request.path directly,
allowing control characters (e.g. newlines or ANSI escape sequences) to
be written unescaped into logs. This could enable log injection or
forgery, letting attackers manipulate log appearance or structure,
especially in logs processed by external systems or viewed in terminals.
(Closes: #1107282)

* CVE-2025-32873: Denial-of-service possibility in strip_tags()

django.utils.html.strip_tags() would be slow to evaluate certain inputs
containing large sequences of incomplete HTML tags. This function is used
to implement the striptags template filter, which was therefore also
vulnerable. strip_tags() now raises a SuspiciousOperation exception if it
encounters an unusually large number of unclosed opening tags.
(Closes: #1104872)

* CVE-2023-41164: Potential denial of service vulnerability in

Read the Full Advisory


Package: python-django
Version: 2:2.2.28-1~deb11u7

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here