Updated python-django packages fix security vulnerabilities
Publication date: 07 Aug 2026Modification date: 07 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-6873 , CVE-2026-7666 , CVE-2026-8404 , CVE-2026-35193 , CVE-2026-48587 , CVE-2026-48588 , CVE-2026-53877 , CVE-2026-53878
Description
The updated package fixes security vulnerabilities:
Signed cookie salt namespace collision in
`django.http.HttpRequest.get_signed_cookie`. (CVE-2026-6873)
Potential unencrypted email transmission via `STARTTLS` in the SMTP
backend. (CVE-2026-7666)
Potential exposure of private data via case-sensitive `Cache-Control`
directives in `UpdateCacheMiddleware`. (CVE-2026-8404)
Potential exposure of private data via missing `Vary: Authorization` in
`UpdateCacheMiddleware`. (CVE-2026-35193)
Potential exposure of private data via whitespace padding in `Vary`
header. (CVE-2026-48587)
Potential exposure of private data via cached `Set-Cookie` response.
(CVE-2026-48588)
Heap buffer over-read in `GDALRaster`. (CVE-2026-53877)
Header injection possibility since `DomainNameValidator` accepted
newlines in input. (CVE-2026-53878)
References
- https://bugs.mageia.org/show_bug.cgi?id=35870
- https://www.openwall.com/lists/oss-security/2026/06/03/10
- https://www.openwall.com/lists/oss-security/2026/07/07/10
- https://www.djangoproject.com/weblog/2026/jul/07/security-releases/
- https://www.cve.org/CVERecord?id=CVE-2026-6873
- https://www.cve.org/CVERecord?id=CVE-2026-7666
- https://www.cve.org/CVERecord?id=CVE-2026-8404
- https://www.cve.org/CVERecord?id=CVE-2026-35193
- https://www.cve.org/CVERecord?id=CVE-2026-48587
- https://www.cve.org/CVERecord?id=CVE-2026-48588
- https://www.cve.org/CVERecord?id=CVE-2026-53877
- https://www.cve.org/CVERecord?id=CVE-2026-53878
SRPMS
10/core
- python-django-5.2.16-1.mga10