stable

python-django4.2-4.2.30-2.el9

FEDORA-EPEL-2026-4d0b588a17 created by salimma a month ago for Fedora EPEL 9
  • Backport fix for CVE-2026-35192 (low): Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST
  • Django 4.2.30 fixes one security issue with severity “moderate” and four security issues with severity “low” in 4.2.29
  • CVE-2026-33033: Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload [moderate]
  • CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation
  • CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin
  • CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable
  • CVE-2026-33034: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass
  • Django 4.2.29 fixes a security issue with severity “moderate” and a security issue with severity “low” in 4.2.28
  • CVE-2026-25673: Potential denial-of-service vulnerability in URLField via Unicode normalization on Windows [moderate]
  • CVE-2026-25674: Potential incorrect permissions on newly created file system objects

This update has been submitted for testing by salimma.

a month ago

This update's test gating status has been changed to 'ignored'.

a month ago

This update has been pushed to testing.

a month ago
User Icon salimma provided feedback a month ago
User Icon salimma provided feedback a month ago
User Icon salimma commented & provided feedback a month ago

ebranch check-update: no issues found (21 reverse dependencies checked)

User Icon salimma commented & provided feedback a month ago

Checking update: FEDORA-EPEL-2026-4d0b588a17

Branch: c9s (@epel)

Updated packages: python-django4.2

Updated Provides (6)

  • python-django4.2 (4.2.28-1.el9 → 4.2.30-2.el9)
  • python-django4.2-bash-completion (4.2.28-1.el9 → 4.2.30-2.el9)
  • python3-django4.2 (4.2.28-1.el9 → 4.2.30-2.el9)
  • python3.9-django4.2 (4.2.28-1.el9 → 4.2.30-2.el9)
  • python3.9dist(django) (4.2.28 → 4.2.30)
  • python3dist(django) (4.2.28 → 4.2.30)

Reverse dependencies

  • kobo: OK
  • osh: OK
  • python-django-allauth: OK
  • python-django-appconf: OK
  • python-django-cache-url: OK
  • python-django-clacks: OK
  • python-django-configurations: OK
  • python-django-extensions: OK
  • python-django-gravatar2: OK
  • python-django-haystack: OK
  • python-django-mailman3: OK
  • python-django-picklefield: OK
  • python-django-q: OK
  • python-django-rest-framework: OK
  • python-django-tastypie: OK
  • python-hyperkitty: OK
  • python-hypothesis: OK
  • python-mailman-web: OK
  • python-postorius: OK
  • python-shortuuid: OK
  • python-xapian-haystack: OK

Summary: all 21 reverse dependencies OK.

BZ#2484689 CVE-2026-35192 python-django4.2: Django: Session theft due to improper cookie handling with cached pages [epel-all]

This update has been submitted for stable by bodhi.

a month ago

This update has been pushed to stable.

a month ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
1
Stable by Time
7 days
Dates
submitted
a month ago
in testing
a month ago
in stable
a month ago
approved
a month ago
BZ#2484689 CVE-2026-35192 python-django4.2: Django: Session theft due to improper cookie handling with cached pages [epel-all]
0
1

Automated Test Results