MGASA-2026-0324

Source
https://advisories.mageia.org/MGASA-2026-0324.html
Import Source
https://advisories.mageia.org/MGASA-2026-0324.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0324
Upstream
Published
2026-08-07T06:29:31Z
Modified
2026-08-07T06:43:38.864269235Z
Summary
Updated python-django packages fix security vulnerabilities
Details

The updated package fixes security vulnerabilities: Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie. (CVE-2026-6873) Potential unencrypted email transmission via STARTTLS in the SMTP backend. (CVE-2026-7666) Potential exposure of private data via case-sensitive Cache-Control directives in UpdateCacheMiddleware. (CVE-2026-8404) Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddleware. (CVE-2026-35193) Potential exposure of private data via whitespace padding in Vary header. (CVE-2026-48587) Potential exposure of private data via cached Set-Cookie response. (CVE-2026-48588) Heap buffer over-read in GDALRaster. (CVE-2026-53877) Header injection possibility since DomainNameValidator accepted newlines in input. (CVE-2026-53878)

References
Credits

Affected packages

Mageia:10 / python-django

Package

Name
python-django
Purl
pkg:rpm/mageia/python-django?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.2.16-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0324.json"