ELA-1648-1 python-django security update

multiple vulnerabilities

2026-02-19
Packagepython-django
Version1:1.10.7-2+deb9u30 (stretch), 1:1.11.29-1+deb10u19 (buster)
Related CVEs CVE-2025-13473 CVE-2026-1207 CVE-2026-1285 CVE-2026-1287 CVE-2026-1312


It was discovered that there were multiple vulnerabilities in Django, the Python-based web-development framework:

In addition, The fix for CVE-2025-6069 in the python3.9 source package which modified the html.parser.HTMLParser class in such a way that changed the behaviour of Django’s strip_tags() method in some edge cases that were tested by Django’s testsuite. As a result of this regression, we have updated the testsuite for the new expected results.



For Debian 10 buster, these problems have been fixed in version 1:1.11.29-1+deb10u19.

For Debian 9 stretch, these problems have been fixed in version 1:1.10.7-2+deb9u30.

We recommend that you upgrade your python-django packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.