{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20704-1","published":"2026-05-06T17:45:29Z","modified":"2026-05-09T18:24:39.364974Z","related":["CVE-2026-35192","CVE-2026-5766","CVE-2026-6907"],"upstream":["CVE-2026-35192","CVE-2026-5766","CVE-2026-6907"],"summary":"Security update for python-Django","details":"This update for python-Django fixes the following issues:\n\nChanges in python-Django:\n\n- CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests\n  via file upload limit bypass (bsc#1264153)\n- CVE-2026-35192: Session fixation via public cached pages and\n  SESSION_SAVE_EVERY_REQUEST (bsc#1264154)\n- CVE-2026-6907: Potential exposure of private data due to incorrect handling\n  of Vary: * in UpdateCacheMiddleware (bsc#1264152)\n","references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264152"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264153"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264154"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35192"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5766"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6907"}]}