Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian 11: Security Update for python-django DLA-4425-1 CVE-2025-64459

debian lts
Calendar Grey December 29, 2025
Dist Debian Esm H88
Discover critical updates for python-django in Debian LTS addressing SQL injection and DoS risks for enhanced application security.

Summary

* CVE-2025-64459: A potential SQL injection via _connector
keyword argument in QuerySet/Q objects. The methods QuerySet
filter(), exclude() and get() as well as the Q() class were
subject to SQL injection when using a suitably crafted dictionary
as the _connector argument.

* CVE-2025-64460: A potential denial-of-service vulnerability in
XML serializer text extraction. An algorithmic complexity issue in
django.core.serializers.xml_serializer.getInnerText() allowed a
remote attacker to cause a potential denial-of-service triggering
CPU and memory exhaustion via a specially crafted XML input
submitted to a service that invokes XML Deserializer. The
vulnerability resulted from repeated string concatenation while
recursively collecting text nodes, which produced superlinear
computation.

For Debian 11 bullseye, these problems have been fixed in version
2:2.2.28-1~deb11u10.

We recommend that you upgrade your python-django packages.

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Package: python-django
Version: 2:2.2.28-1~deb11u10
Debian Bug: 1121788

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here