Updated python-django packages fix security vulnerabilities
Publication date: 27 Aug 2026Modification date: 27 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-15307 , CVE-2026-15337 , CVE-2026-15830 , CVE-2026-15920
Description
CVE-2026-15307: Server-side file-write and request forgery via spatial
lookups
CVE-2026-15337: Potential denial-of-service vulnerability in
`check_for_language()`
CVE-2026-15830: Potential denial-of-service vulnerability via nested
geometry collections
CVE-2026-15920: Potential cross-site scripting via `URLField` values in
the admin
References
- https://bugs.mageia.org/show_bug.cgi?id=36132
- https://www.openwall.com/lists/oss-security/2026/08/04/6
- https://docs.djangoproject.com/en/dev/releases/5.2.17/
- https://www.cve.org/CVERecord?id=CVE-2026-15307
- https://www.cve.org/CVERecord?id=CVE-2026-15337
- https://www.cve.org/CVERecord?id=CVE-2026-15830
- https://www.cve.org/CVERecord?id=CVE-2026-15920
SRPMS
10/core
- python-django-5.2.17-1.mga10