This update for python-djangorestframework, python-Django fixes the
following issues:
python-djangorestframework:
- CVE-2024-21520: Fixed improper input sanitization before splitting and
joining with 'br' tags (boo#1227077)
- Tests can be run only on (newer) python311 stack
- Make it at least installable on python3 stack (no guarantees for it to
run)
- Use sle15allpythons to get the Python 3.6 packages too (jsc#PED-8919)
python-Django:
- CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin (boo#1261731)
- CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable (boo#1261732)
- CVE-2026-33033: Potential denial-of-service vulnerability in
MultiPartParser via base64-encoded file upload (boo#1261722)
- CVE-2026-25674: Fixed a race condition that could lead to potential
incorrect permissions on newly created file system objects (boo#1259142)
- Let django-admin be the master alternative
* django-admin.py was dropped...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP6:
zypper in -t patch openSUSE-2026-138=1
- openSUSE Backports SLE-15-SP6 (noarch):
python3-Django-2.2.28-bp156.39.1
python3-djangorestframework-3.14.0-bp156.2.3.1
python311-djangorestframework-3.14.0-bp156.2.3.1
https://www.suse.com/security/cve/CVE-2024-21520.html
https://www.suse.com/security/cve/CVE-2026-25674.html
https://www.suse.com/security/cve/CVE-2026-33033.html
https://www.suse.com/security/cve/CVE-2026-4277.html
https://www.suse.com/security/cve/CVE-2026-4292.html
https://bugzilla.suse.com/1227077
https://bugzilla.suse.com/1259142
https://bugzilla.suse.com/1261722
https://bugzilla.suse.com/1261731
https://bugzilla.suse.com/1261732
Get the latest Linux and open source security news straight to your inbox.