ELA-1835-1 python-django security update

multiple vulnerabilities

2026-09-29
Packagepython-django
Version1:1.10.7-2+deb9u32 (buster)
Related CVEs CVE-2026-48587 CVE-2026-48588 CVE-2026-53877


Multiple vulnerabilities were discovered in Django, the Python-based web development framework:



For Debian 10 buster, these problems have been fixed in version 1:1.11.29-1+deb10u21.

For Debian 11 bullseye, these problems have been fixed in version 2:2.2.28-1~deb11u14.

For Debian 9 stretch, these problems have been fixed in version 1:1.10.7-2+deb9u32.

We recommend that you upgrade your python-django packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.