openSUSE-SU-2026:20704-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20704-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:20704-1
Upstream
CVE (3)
Related
Published
2026-05-06T17:45:29Z
Modified
2026-05-09T18:29:27Z
Summary
Security update for python-Django
Details

This update for python-Django fixes the following issues:

Changes in python-Django:

  • CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass (bsc#1264153)
  • CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST (bsc#1264154)
  • CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware (bsc#1264152)
References

Affected packages