Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian LTS python-django DLA-4458-1 Multiple Security Issues

debian lts
Calendar Grey January 28, 2026
Dist Debian Esm H88
Explore critical security fixes for python-django on Debian LTS addressing multiple vulnerabilities including DoS and SQL injection.

Summary

- - CVE-2024-39614: Fix a potential denial-of-service in
django.utils.translation.get_supported_language_variant. This
method was subject to a potential DoS attack when used with very
long strings containing specific characters. To mitigate this
vulnerability, the language code provided to
get_supported_language_variant is now parsed up to a maximum length
of 500 characters.

- - CVE-2024-45231: Potential user email enumeration via response
status on password reset. Due to unhandled email sending failures,
the django.contrib.auth.forms.PasswordResetForm class allowed
remote attackers to enumerate user emails by issuing password reset
requests and observing the outcomes. To mitigate this risk,
exceptions occurring during password reset email sending are now
handled and logged using the django.contrib.auth logger.

- - CVE-2024-42005: Potential SQL injection in QuerySet.values() and
values_list(). QuerySet.values() and values_list() methods on

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: python-django
Version: 2:2.2.28-1~deb11u11

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here