Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Django could be made to log injection if received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-7555-3 June 17, 2025 python-django vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Django could be made to log injection if received specially crafted input. Software Description: - python-django: High-level Python web development framework Details: USN-7555-1 fixed a vulnerability in Django. This update provides an additional fix for Ubuntu 20.04 LTS. Original advisory details: It was discovered that Django incorrectly handled certain unescaped request paths. An attacker could possibly use this issue to perform a log injection. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS python3-django 2:2.2.12-1ubuntu0.29+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7555-3 https://ubuntu.com/security/notices/USN-7555-2 https://ubuntu.com/security/notices/USN-7555-1 https://bugs.launchpad.net/ubuntu/+source/python-django/+bug/2113924 . Ubuntu Security Notice USN-7555-4 tackles the python-django flaw, mitigating log injection risks in Ubuntu 22.04.. django security, log injection, ubuntu update, python framework, release notes. . Severity: Important. LinuxSecurity.com Team
An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on . MGASA-2025-0153 - Updated python-django packages fix security vulnerability Publication date: 11 May 2025 URL: https://advisories.mageia.org/MGASA-2025-0153.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-32873 An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags(). (CVE-2025-32873) References: - https://bugs.mageia.org/show_bug.cgi?id=34259 - https://ubuntu.com/security/notices/USN-7501-1 - https://www.cve.org/CVERecord?id=CVE-2025-32873 SRPMS: - 9/core/python-django-4.1.13-1.4.mga9 . Django releases before 4.2.21 are vulnerable to a Denial of Service threat due to improperly closed HTML tags. It's recommended to update to the latest secure versions.. Django DoS issue, Mageia security advisory, python django update. . Severity: Important. LinuxSecurity.com Team
Django could be made to crash if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-7501-2 May 07, 2025 python-django vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Django could be made to crash if it received specially crafted network traffic. Software Description: - python-django: High-level Python web development framework Details: USN-7501-1 fixed a vulnerability in Django. This update provides the corresponding update for Ubuntu 18.04 LTS. Original advisory details: Elias Myllymäki discovered that Django incorrectly handled stripping large sequences of incomplete HTML tags. A remote attacker could possibly use this issue to cause Django to consume resources, leading to a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS python-django 1:1.11.11-1ubuntu1.21+esm11 Available with Ubuntu Pro python3-django 1:1.11.11-1ubuntu1.21+esm11 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7501-2 https://ubuntu.com/security/notices/USN-7501-1 CVE-2025-32873 . Upgrade Ubuntu 18.04 LTS to address Django crash exploit from malicious requests. Enhance your system's security now!. django crash, ubuntu 18.04, security update, denial of service, resource management. . Severity: Critical. LinuxSecurity.com Team
ix for CVE-2025-26699: Potential denial-of-service vulnerability in django.utils.text.wrap(). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-da3777e8c4 2025-03-18 01:10:56.300680+00:00 -------------------------------------------------------------------------------- Name : python-django4.2 Product : Fedora 41 Version : 4.2.20 Release : 1.fc41 URL : https://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. -------------------------------------------------------------------------------- Update Information: ix for CVE-2025-26699: Potential denial-of-service vulnerability in django.utils.text.wrap() -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 8 2025 Michel Lind - 4.2.20-1 - Update to version 4.2.20; Fixes: RHBZ#2350882 - Fix for CVE-2025-26699: Potential denial-of-service vulnerability in django.utils.text.wrap() * Sat Jan 18 2025 Fedora Release Engineering - 4.2.16-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2350882 - CVE-2025-26699: Potential denial-of-service vulnerability in django.utils.text.wrap() https://bugzilla.redhat.com/show_bug.cgi?id=2350882 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-da3777e8c4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packagesare signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
ix for CVE-2025-26699: Potential denial-of-service vulnerability in django.utils.text.wrap(). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e3df06bb77 2025-03-18 00:15:21.924451+00:00 -------------------------------------------------------------------------------- Name : python-django4.2 Product : Fedora 42 Version : 4.2.20 Release : 1.fc42 URL : https://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. -------------------------------------------------------------------------------- Update Information: ix for CVE-2025-26699: Potential denial-of-service vulnerability in django.utils.text.wrap() -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 8 2025 Michel Lind - 4.2.20-1 - Update to version 4.2.20; Fixes: RHBZ#2350882 - Fix for CVE-2025-26699: Potential denial-of-service vulnerability in django.utils.text.wrap() * Sat Jan 18 2025 Fedora Release Engineering - 4.2.16-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2350882 - CVE-2025-26699: Potential denial-of-service vulnerability in django.utils.text.wrap() https://bugzilla.redhat.com/show_bug.cgi?id=2350882 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e3df06bb77' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packagesare signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for python-Django ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0408-1 Rating: moderate References: #1234232 Cross-References: CVE-2024-53907 CVSS scores: CVE-2024-53907 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-Django fixes the following issues: - CVE-2024-53907: Fixed potential denial-of-service in django.utils.html.strip_tags() (boo#1234232). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-408=1 Package List: References: https://www.suse.com/security/cve/CVE-2024-53907.html https://bugzilla.suse.com/1234232 . Addresses a denial-of-service vulnerability in django.utils.html.strip_tags through an openSUSE Security Update for python-Django.. python-Django, openSUSE, security advisory, moderate severity, denial-of-service. . LinuxSecurity.com Team
Several security issues were fixed in Django.. ========================================================================== Ubuntu Security Notice USN-6946-1 August 06, 2024 python-django vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Django. Software Description: - python-django: High-level Python web development framework Details: It was discovered that Django incorrectly handled certain strings in floatformat function. An attacker could possibly use this issue to cause a memory exhaustion. (CVE-2024-41989) It was discovered that Django incorrectly handled very large inputs. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-41990) It was discovered that Django in AdminURLFieldWidget incorrectly handled certain inputs with a very large number of Unicode characters. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-41991) It was discovered that Django incorrectly handled certain JSON objects. An attacker could possibly use this issue to cause a potential SQL injection. This issue only affected Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-42005) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python3-django 3:4.2.11-1ubuntu1.2 Ubuntu 22.04 LTS python3-django 2:3.2.12-2ubuntu1.13 Ubuntu 20.04 LTS python3-django 2:2.2.12-1ubuntu0.24 Ubuntu 18.04 LTS python-django 1:1.11.11-1ubuntu1.21+esm6 Available with Ubuntu Pro python3-django 1:1.11.11-1ubuntu1.21+esm6 Available with Ubuntu Pro In general, a standard system update will make all the necessarychanges. References: https://ubuntu.com/security/notices/USN-6946-1 CVE-2024-41989, CVE-2024-41990, CVE-2024-41991, CVE-2024-42005 Package Information: https://launchpad.net/ubuntu/+source/python-django/3:4.2.11-1ubuntu1.2 https://launchpad.net/ubuntu/+source/python-django/2:3.2.12-2ubuntu1.13 https://launchpad.net/ubuntu/+source/python-django/2:2.2.12-1ubuntu0.24 . Ubuntu Security Notice USN-6947-1 provides critical updates for PostgreSQL vulnerabilities with detailed remediation steps and impacted versions.. Django Security Advisory, Ubuntu Security Notice, Python Framework Updates. . LinuxSecurity.com Team
Security fixes for CVE-2024-27351 Potential regular expression DOS in django.utils.text.Truncator.words() CVE-2024-24680 denial-of-service in intcomma template filter CVE-2023-43665 Denial-of-service possibility in django.utils.text.Truncator. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-84fbbbb914 2024-04-20 02:13:26.365177 -------------------------------------------------------------------------------- Name : python-django3 Product : Fedora 38 Version : 3.2.25 Release : 2.fc38 URL : https://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. -------------------------------------------------------------------------------- Update Information: Security fixes for CVE-2024-27351 Potential regular expression DOS in django.utils.text.Truncator.words() CVE-2024-24680 denial-of-service in intcomma template filter CVE-2023-43665 Denial-of-service possibility in django.utils.text.Truncator CVE-2023-41164 Potential DOS vulnerability in django.utils.encoding.uri_to_iri() CVE-2023-36053 Potential regular expression denial of service vulnerability in EmailValidator/URLValidator -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 11 2024 Michel Lind - 3.2.25-2 - Make test bcond work (tests are enabled by default) * Thu Apr 11 2024 Michel Lind - 3.2.25-1 - Update to 3.2.25 - Mark as deprecated due to EOL - Update list of bundled dependencies - Declare licenses of bundled dependencies - Add virtual Provides and Conflicts to allow swapping Django stacks - Drop unneeded patches -------------------------------------------------------------------------------- References: [ 1 ] Bug#2219382 - CVE-2023-36053 python-django3: python-django: Potential regular expression denial of service vulnerability in EmailValidator/URLValidator [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2219382 [ 2 ] Bug #2237871 - CVE-2023-41164 python-django3: python-django: Potential denial of service vulnerability in ``django.utils.encoding.uri_to_iri()`` [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2237871 [ 3 ] Bug #2242181 - CVE-2023-43665 python-django3: python-django: Denial-of-service possibility in django.utils.text.Truncator [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2242181 [ 4 ] Bug #2263506 - CVE-2024-24680 python-django3: Django: denial-of-service in ``intcomma`` template filter [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2263506 [ 5 ] Bug #2267655 - CVE-2024-27351 python-django3: python-django: Potential regular expression denial-of-service in django.utils.text.Truncator.words() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2267655 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-84fbbbb914' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.