Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 42: FEDORA-2025-6de2ab1d25 Critical python-django DoS Threats

fedora
Calendar Grey June 18, 2025
Dist Fedora Esm H88
Ubuntu 23.10 enhances nodejs to combat significant vulnerabilities such as privilege escalation and data leakage risks.
Fixes CVE-2025-32873: Denial-of-service possibility in strip_tags() Fixes CVE-2025-48432: Potential log injection via unescaped request path

Summary

Django is a high-level Python Web framework that encourages rapid

development and a clean, pragmatic design. It focuses on automating as

much as possible and adhering to the DRY (Don't Repeat Yourself)

principle.

Update Information:

Fixes CVE-2025-32873: Denial-of-service possibility in strip_tags() Fixes CVE-2025-48432: Potential log injection via unescaped request path

Change Log

* Sun Jun 8 2025 Michel Lind - 4.2.22-1 - Update to version 4.2.22 - Fixes CVE-2025-32873: Denial-of-service possibility in strip_tags() - Fixes CVE-2025-48432: Potential log injection via unescaped request path - Revert setuptools bump; we don't need it and don't have the needed version - Rebase Python 3.13 patch

References


[ 1 ] Bug #2365046 - CVE-2025-32873 python-django4.2: Django StripTags Denial of Service [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2365046

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-6de2ab1d25' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-django4.2
Product: Fedora 42
Version: 4.2.22
Release: 1.fc42
Summary: A high-level Python Web framework

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here