Security update for python-Django
This update for python-Django fixes the following issues: Changes in python-Django: - CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation (bsc#1261729) - CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin (bsc#1261731) - CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable (bsc#1261732) - CVE-2026-33033: Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload (bsc#1261722) - CVE-2026-33034: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass (bsc#1261724)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for python-Django fixes the following issues: Changes in python-Django: - CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation (bsc#1261729) - CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin (bsc#1261731) - CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable (bsc#1261732) - CVE-2026-33033: Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload (bsc#1261722) - CVE-2026-33034: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass (bsc#1261724)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1261722
- https://bugzilla.suse.com/1261724
- https://bugzilla.suse.com/1261729
- https://bugzilla.suse.com/1261731
- https://bugzilla.suse.com/1261732
- https://www.suse.com/security/cve/CVE-2026-33033
- https://www.suse.com/security/cve/CVE-2026-33034
- https://www.suse.com/security/cve/CVE-2026-3902
- https://www.suse.com/security/cve/CVE-2026-4277
- https://www.suse.com/security/cve/CVE-2026-4292