| Package | python-django |
|---|---|
| Version | 1:1.10.7-2+deb9u32 (buster) |
| Related CVEs | CVE-2026-48587 CVE-2026-48588 CVE-2026-53877 |
Multiple vulnerabilities were discovered in Django, the Python-based web development framework:
-
CVE-2026-48587: Potential exposure of private data via whitespace padding in theVaryheader.UpdateCacheMiddlewareincorrectly cached responses whoseVaryheader values contained leading or trailing whitespace. Becausehas_vary_headerfailed to strip that whitespace, a response with a “Vary: *” header (note the trailing space) was not recognized as containing the wildcard, causing it to be stored and potentially served from the cache when it should not have been. (stretch and buster only) -
CVE-2026-48588:UpdateCacheMiddlewareand the@cache_pagedecorator cached responses that vary on cookies when the incoming request carried unrelated cookies which allowed remote attackers to read private data from the shared cache. -
CVE-2026-53877:django.contrib.gis.gdal.GDALRasterover-read its in-memory buffer when constructed from a bytes object, which could disclose adjacent memory or cause service degradation via a potential segmentation fault when thevsi_bufferproperty is accessed. (bullseye only)
For Debian 10 buster, these problems have been fixed in version 1:1.11.29-1+deb10u21.
For Debian 11 bullseye, these problems have been fixed in version 2:2.2.28-1~deb11u14.
For Debian 9 stretch, these problems have been fixed in version 1:1.10.7-2+deb9u32.
We recommend that you upgrade your python-django packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.