Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 47 articles for you...
172

Ubuntu 20.04 LTS USN-7555-3: Django Log Injection Risk Identified

Django could be made to log injection if received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-7555-3 June 17, 2025 python-django vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Django could be made to log injection if received specially crafted input. Software Description: - python-django: High-level Python web development framework Details: USN-7555-1 fixed a vulnerability in Django. This update provides an additional fix for Ubuntu 20.04 LTS. Original advisory details: It was discovered that Django incorrectly handled certain unescaped request paths. An attacker could possibly use this issue to perform a log injection. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS python3-django 2:2.2.12-1ubuntu0.29+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7555-3 https://ubuntu.com/security/notices/USN-7555-2 https://ubuntu.com/security/notices/USN-7555-1 https://bugs.launchpad.net/ubuntu/+source/python-django/+bug/2113924 . Ubuntu Security Notice USN-7555-4 tackles the python-django flaw, mitigating log injection risks in Ubuntu 22.04.. django security, log injection, ubuntu update, python framework, release notes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 17, 2025 Important Ubuntu
203

Mageia 9: 2025-0153 Moderate Security Risk in Django Can Lead to DoS

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on . MGASA-2025-0153 - Updated python-django packages fix security vulnerability Publication date: 11 May 2025 URL: https://advisories.mageia.org/MGASA-2025-0153.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-32873 An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags(). (CVE-2025-32873) References: - https://bugs.mageia.org/show_bug.cgi?id=34259 - https://ubuntu.com/security/notices/USN-7501-1 - https://www.cve.org/CVERecord?id=CVE-2025-32873 SRPMS: - 9/core/python-django-4.1.13-1.4.mga9 . Django releases before 4.2.21 are vulnerable to a Denial of Service threat due to improperly closed HTML tags. It's recommended to update to the latest secure versions.. Django DoS issue, Mageia security advisory, python django update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 11, 2025 Important Mageia
172

Ubuntu 18.04 LTS USN-7501-2: Django denial of service issue

Django could be made to crash if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-7501-2 May 07, 2025 python-django vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Django could be made to crash if it received specially crafted network traffic. Software Description: - python-django: High-level Python web development framework Details: USN-7501-1 fixed a vulnerability in Django. This update provides the corresponding update for Ubuntu 18.04 LTS. Original advisory details: Elias Myllymäki discovered that Django incorrectly handled stripping large sequences of incomplete HTML tags. A remote attacker could possibly use this issue to cause Django to consume resources, leading to a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS python-django 1:1.11.11-1ubuntu1.21+esm11 Available with Ubuntu Pro python3-django 1:1.11.11-1ubuntu1.21+esm11 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7501-2 https://ubuntu.com/security/notices/USN-7501-1 CVE-2025-32873 . Upgrade Ubuntu 18.04 LTS to address Django crash exploit from malicious requests. Enhance your system's security now!. django crash, ubuntu 18.04, security update, denial of service, resource management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 07, 2025 Critical Ubuntu
89

Fedora 41: python-django4.2 2025-da3777e8c4 Security Advisory Updates

ix for CVE-2025-26699: Potential denial-of-service vulnerability in django.utils.text.wrap(). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-da3777e8c4 2025-03-18 01:10:56.300680+00:00 -------------------------------------------------------------------------------- Name : python-django4.2 Product : Fedora 41 Version : 4.2.20 Release : 1.fc41 URL : https://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. -------------------------------------------------------------------------------- Update Information: ix for CVE-2025-26699: Potential denial-of-service vulnerability in django.utils.text.wrap() -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 8 2025 Michel Lind - 4.2.20-1 - Update to version 4.2.20; Fixes: RHBZ#2350882 - Fix for CVE-2025-26699: Potential denial-of-service vulnerability in django.utils.text.wrap() * Sat Jan 18 2025 Fedora Release Engineering - 4.2.16-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2350882 - CVE-2025-26699: Potential denial-of-service vulnerability in django.utils.text.wrap() https://bugzilla.redhat.com/show_bug.cgi?id=2350882 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-da3777e8c4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packagesare signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Learn about the recent updates for Fedora 41 addressing the denial-of-service issue in python-django 4.2 related to CVE-2025-26699.. cve-2025-26699, potential, denial-of-service, vulnerability, django, utils, wrap(), -------. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 18, 2025 Important Fedora
89

Fedora 42: python-django4.2 2025-e3df06bb77 Security Advisory Updates

ix for CVE-2025-26699: Potential denial-of-service vulnerability in django.utils.text.wrap(). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e3df06bb77 2025-03-18 00:15:21.924451+00:00 -------------------------------------------------------------------------------- Name : python-django4.2 Product : Fedora 42 Version : 4.2.20 Release : 1.fc42 URL : https://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. -------------------------------------------------------------------------------- Update Information: ix for CVE-2025-26699: Potential denial-of-service vulnerability in django.utils.text.wrap() -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 8 2025 Michel Lind - 4.2.20-1 - Update to version 4.2.20; Fixes: RHBZ#2350882 - Fix for CVE-2025-26699: Potential denial-of-service vulnerability in django.utils.text.wrap() * Sat Jan 18 2025 Fedora Release Engineering - 4.2.16-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2350882 - CVE-2025-26699: Potential denial-of-service vulnerability in django.utils.text.wrap() https://bugzilla.redhat.com/show_bug.cgi?id=2350882 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e3df06bb77' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packagesare signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Django 4.2.20 update addresses a denial-of-service flaw, essential for maintaining security on Fedora 42 systems.. cve-2025-26699, potential, denial-of-service, vulnerability, django, utils, wrap(), -------. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 18, 2025 Important Fedora
202

openSUSE: 2024:0408-1 moderate: python-Django DoS Issue

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for python-Django ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0408-1 Rating: moderate References: #1234232 Cross-References: CVE-2024-53907 CVSS scores: CVE-2024-53907 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-Django fixes the following issues: - CVE-2024-53907: Fixed potential denial-of-service in django.utils.html.strip_tags() (boo#1234232). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-408=1 Package List: References: https://www.suse.com/security/cve/CVE-2024-53907.html https://bugzilla.suse.com/1234232 . Addresses a denial-of-service vulnerability in django.utils.html.strip_tags through an openSUSE Security Update for python-Django.. python-Django, openSUSE, security advisory, moderate severity, denial-of-service. . LinuxSecurity.com Team

Calendar%202 Dec 14, 2024 OpenSUSE
172

Ubuntu: USN-6946-1 Moderate: Django Denial Of Service and Memory Issues

Several security issues were fixed in Django.. ========================================================================== Ubuntu Security Notice USN-6946-1 August 06, 2024 python-django vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Django. Software Description: - python-django: High-level Python web development framework Details: It was discovered that Django incorrectly handled certain strings in floatformat function. An attacker could possibly use this issue to cause a memory exhaustion. (CVE-2024-41989) It was discovered that Django incorrectly handled very large inputs. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-41990) It was discovered that Django in AdminURLFieldWidget incorrectly handled certain inputs with a very large number of Unicode characters. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-41991) It was discovered that Django incorrectly handled certain JSON objects. An attacker could possibly use this issue to cause a potential SQL injection. This issue only affected Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-42005) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python3-django 3:4.2.11-1ubuntu1.2 Ubuntu 22.04 LTS python3-django 2:3.2.12-2ubuntu1.13 Ubuntu 20.04 LTS python3-django 2:2.2.12-1ubuntu0.24 Ubuntu 18.04 LTS python-django 1:1.11.11-1ubuntu1.21+esm6 Available with Ubuntu Pro python3-django 1:1.11.11-1ubuntu1.21+esm6 Available with Ubuntu Pro In general, a standard system update will make all the necessarychanges. References: https://ubuntu.com/security/notices/USN-6946-1 CVE-2024-41989, CVE-2024-41990, CVE-2024-41991, CVE-2024-42005 Package Information: https://launchpad.net/ubuntu/+source/python-django/3:4.2.11-1ubuntu1.2 https://launchpad.net/ubuntu/+source/python-django/2:3.2.12-2ubuntu1.13 https://launchpad.net/ubuntu/+source/python-django/2:2.2.12-1ubuntu0.24 . Ubuntu Security Notice USN-6947-1 provides critical updates for PostgreSQL vulnerabilities with detailed remediation steps and impacted versions.. Django Security Advisory, Ubuntu Security Notice, Python Framework Updates. . LinuxSecurity.com Team

Calendar%202 Aug 06, 2024 Ubuntu
89

Fedora 38: FEDORA-2024-84fbbbb914 Critical Django DoS Threats

Security fixes for CVE-2024-27351 Potential regular expression DOS in django.utils.text.Truncator.words() CVE-2024-24680 denial-of-service in intcomma template filter CVE-2023-43665 Denial-of-service possibility in django.utils.text.Truncator. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-84fbbbb914 2024-04-20 02:13:26.365177 -------------------------------------------------------------------------------- Name : python-django3 Product : Fedora 38 Version : 3.2.25 Release : 2.fc38 URL : https://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. -------------------------------------------------------------------------------- Update Information: Security fixes for CVE-2024-27351 Potential regular expression DOS in django.utils.text.Truncator.words() CVE-2024-24680 denial-of-service in intcomma template filter CVE-2023-43665 Denial-of-service possibility in django.utils.text.Truncator CVE-2023-41164 Potential DOS vulnerability in django.utils.encoding.uri_to_iri() CVE-2023-36053 Potential regular expression denial of service vulnerability in EmailValidator/URLValidator -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 11 2024 Michel Lind - 3.2.25-2 - Make test bcond work (tests are enabled by default) * Thu Apr 11 2024 Michel Lind - 3.2.25-1 - Update to 3.2.25 - Mark as deprecated due to EOL - Update list of bundled dependencies - Declare licenses of bundled dependencies - Add virtual Provides and Conflicts to allow swapping Django stacks - Drop unneeded patches -------------------------------------------------------------------------------- References: [ 1 ] Bug#2219382 - CVE-2023-36053 python-django3: python-django: Potential regular expression denial of service vulnerability in EmailValidator/URLValidator [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2219382 [ 2 ] Bug #2237871 - CVE-2023-41164 python-django3: python-django: Potential denial of service vulnerability in ``django.utils.encoding.uri_to_iri()`` [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2237871 [ 3 ] Bug #2242181 - CVE-2023-43665 python-django3: python-django: Denial-of-service possibility in django.utils.text.Truncator [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2242181 [ 4 ] Bug #2263506 - CVE-2024-24680 python-django3: Django: denial-of-service in ``intcomma`` template filter [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2263506 [ 5 ] Bug #2267655 - CVE-2024-27351 python-django3: python-django: Potential regular expression denial-of-service in django.utils.text.Truncator.words() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2267655 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-84fbbbb914' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Improvements to Fedora's python-django3 mitigate severe denial-of-service risks and bolster security measures.. Fedora Security, Python Django Security, DOS Threats Update, Django Security Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 20, 2024 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200