{"schema_version":"1.7.5","id":"SUSE-SU-2026:1740-1","published":"2026-05-07T07:00:32Z","modified":"2026-05-08T08:15:06.762076Z","related":["CVE-2026-33033","CVE-2026-33034","CVE-2026-35192","CVE-2026-3902","CVE-2026-4277","CVE-2026-4292","CVE-2026-5766","CVE-2026-6907"],"upstream":["CVE-2026-33033","CVE-2026-33034","CVE-2026-35192","CVE-2026-3902","CVE-2026-4277","CVE-2026-4292","CVE-2026-5766","CVE-2026-6907"],"summary":"Security update for python-Django","details":"This update for python-Django fixes the following issues\n\n- CVE-2026-3902: headers spoofing by exploiting an ambiguous mapping of two header variants in `ASGIRequest` requests\n  (bsc#1261729).\n- CVE-2026-4277: permissions on inline model instances were not validated on submission of forged POST data in\n  GenericInlineModelAdmin (bsc#1261731).\n- CVE-2026-4292: admin changelist forms using ModelAdmin.list_editable incorrectly allowed new instances to be created\n  via forged POST data (bsc#1261732).\n- CVE-2026-5766: potential denial-of-service vulnerability in ASGI requests via file upload limit bypass (bsc#1264153).\n- CVE-2026-6907: potential exposure of private data due to incorrect handling of `Vary: *` in `UpdateCacheMiddleware`\n  (bsc#1264152).\n- CVE-2026-33033: denial of service via missing or understated Content-Length header in ASGI requests (bsc#1261722).\n- CVE-2026-33034: ASGI requests with a missing or understated Content-Length header could bypass the\n  `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading HttpRequest.body (bsc#1261724).\n- CVE-2026-35192: session fixation via public cached pages and `SESSION_SAVE_EVERY_REQUEST` (bsc#1264154).\n","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261740-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261722"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261724"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261729"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261731"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261732"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264152"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264153"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264154"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33033"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33034"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35192"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3902"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4277"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4292"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5766"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6907"}]}