{"schema_version":"1.7.5","id":"SUSE-SU-2026:2318-1","published":"2026-06-09T13:22:04Z","modified":"2026-06-10T18:24:12.358422482Z","related":["CVE-2026-35193","CVE-2026-48587","CVE-2026-6873","CVE-2026-7666","CVE-2026-8404"],"upstream":["CVE-2026-35193","CVE-2026-48587","CVE-2026-6873","CVE-2026-7666","CVE-2026-8404"],"summary":"Security update for python-Django","details":"This update for python-Django fixes the following issues\n\n- CVE-2026-6873: signed cookie salt namespace collision in `django.http.HttpRequest.get_signed_cookie` (bsc#1267578).\n- CVE-2026-7666: potential unencrypted email transmission via `STARTTLS` in the SMTP backend (bsc#1267579).\n- CVE-2026-8404: potential exposure of private data via case-sensitive `Cache-Control` directives in\n  `UpdateCacheMiddleware` (bsc#1267580).\n- CVE-2026-35193: potential exposure of private data via missing `Vary: Authorization` in `UpdateCacheMiddleware`\n  (bsc#1267576).\n- CVE-2026-48587: potential exposure of private data via whitespace padding in `Vary` header (bsc#1267577).\n","affected":[{"package":{"name":"python-Django","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/python-Django&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.11-150600.3.59.1"}]}],"ecosystem_specific":{"binaries":[{"python311-Django":"4.2.11-150600.3.59.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2318-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262318-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267576"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267577"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267578"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267579"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267580"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35193"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48587"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6873"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-7666"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8404"}]}