{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20937-1","published":"2026-06-10T12:31:15Z","modified":"2026-06-13T18:24:19.273008391Z","related":["CVE-2026-35193","CVE-2026-48587","CVE-2026-6873","CVE-2026-7666","CVE-2026-8404"],"upstream":["CVE-2026-35193","CVE-2026-48587","CVE-2026-6873","CVE-2026-7666","CVE-2026-8404"],"summary":"Security update for python-Django","details":"This update for python-Django fixes the following issues:\n\nChanges in python-Django:\n\n- CVE-2026-6873: Signed cookie salt namespace collision (bsc#1267578)\n- CVE-2026-7666: Potential unencrypted email transmission via STARTTLS in the SMTP backend (bsc#1267579)\n- CVE-2026-8404: Potential exposure of private data via case-sensitive Cache-Control directives (bsc#1267580)\n- CVE-2026-35193: Potential exposure of private data via missing Vary: Authorization (bsc#1267576)\n- CVE-2026-48587: Potential exposure of private data via whitespace padding in Vary header (bsc#1267577)\n","affected":[{"package":{"name":"python-Django","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/python-Django&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.4-bp160.9.1"}]}],"ecosystem_specific":{"binaries":[{"python313-Django":"5.2.4-bp160.9.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20937-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267576"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267577"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267578"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267579"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267580"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35193"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48587"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6873"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-7666"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8404"}]}