{"id":"openSUSE-SU-2026:21543-1","summary":"Security update for python-Django","details":"This update for python-Django fixes the following issues:\n\nChanges in python-Django:\n\n- CVE-2026-15307: server-side file-write and request forgery via spatial lookups (bsc#1272997)\n- CVE-2026-15337: potential denial-of-service vulnerability in `check_for_language()` (bsc#1272998)\n- CVE-2026-15830: potential denial-of-service vulnerability via nested geometry collections (bsc#1272999)\n- CVE-2026-15920: potential cross-site scripting via `URLField` values in the admin (bsc#1273000)\n","modified":"2026-08-08T18:23:36.629620961Z","published":"2026-08-06T14:20:58Z","related":["CVE-2026-15307","CVE-2026-15337","CVE-2026-15830","CVE-2026-15920"],"upstream":["CVE-2026-15307","CVE-2026-15337","CVE-2026-15830","CVE-2026-15920"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272997"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272998"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272999"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273000"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15307"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15337"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15830"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15920"}],"affected":[{"package":{"name":"python-Django","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/python-Django&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.4-bp160.11.1"}]}],"ecosystem_specific":{"binaries":[{"python313-Django":"5.2.4-bp160.11.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21543-1.json"}}],"schema_version":"1.8.0"}