Security update for python-Django
This update for python-Django fixes the following issues: Changes in python-Django: - CVE-2026-6873: Signed cookie salt namespace collision (bsc#1267578) - CVE-2026-7666: Potential unencrypted email transmission via STARTTLS in the SMTP backend (bsc#1267579) - CVE-2026-8404: Potential exposure of private data via case-sensitive Cache-Control directives (bsc#1267580) - CVE-2026-35193: Potential exposure of private data via missing Vary: Authorization (bsc#1267576) - CVE-2026-48587: Potential exposure of private data via whitespace padding in Vary header (bsc#1267577)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for python-Django fixes the following issues: Changes in python-Django: - CVE-2026-6873: Signed cookie salt namespace collision (bsc#1267578) - CVE-2026-7666: Potential unencrypted email transmission via STARTTLS in the SMTP backend (bsc#1267579) - CVE-2026-8404: Potential exposure of private data via case-sensitive Cache-Control directives (bsc#1267580) - CVE-2026-35193: Potential exposure of private data via missing Vary: Authorization (bsc#1267576) - CVE-2026-48587: Potential exposure of private data via whitespace padding in Vary header (bsc#1267577)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1267576
- https://bugzilla.suse.com/1267577
- https://bugzilla.suse.com/1267578
- https://bugzilla.suse.com/1267579
- https://bugzilla.suse.com/1267580
- https://www.suse.com/security/cve/CVE-2026-35193
- https://www.suse.com/security/cve/CVE-2026-48587
- https://www.suse.com/security/cve/CVE-2026-6873
- https://www.suse.com/security/cve/CVE-2026-7666
- https://www.suse.com/security/cve/CVE-2026-8404