USN-8848-1: Django vulnerabilities

Publication date

30 September 2026

Overview

Several security issues were fixed in Django.


Packages

Details

Bence Nagy discovered that GeoDjango in Django incorrectly handled spatial
lookups when processing untrusted input. A remote attacker could possibly
use this issue to make outbound network requests, write arbitrary files, or
execute arbitrary code. This issue was only addressed in Ubuntu 22.04 LTS,
Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-15307)

Ahmad Sadeddin discovered that Django UpdateCacheMiddleware incorrectly
cached requests where the Vary header contained an asterisk. A remote
attacker could possibly use this issue to obtain sensitive information.
(CVE-2026-6907)

Ahmed Badawe discovered that Django did not properly parse Cache-Control
response directives case-insensitively under certain circumstances. A
remote attacker could possibly use this issue to view sensitive information
from responses that were incorrectly cached. This issue...

Bence Nagy discovered that GeoDjango in Django incorrectly handled spatial
lookups when processing untrusted input. A remote attacker could possibly
use this issue to make outbound network requests, write arbitrary files, or
execute arbitrary code. This issue was only addressed in Ubuntu 22.04 LTS,
Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-15307)

Ahmad Sadeddin discovered that Django UpdateCacheMiddleware incorrectly
cached requests where the Vary header contained an asterisk. A remote
attacker could possibly use this issue to obtain sensitive information.
(CVE-2026-6907)

Ahmed Badawe discovered that Django did not properly parse Cache-Control
response directives case-insensitively under certain circumstances. A
remote attacker could possibly use this issue to view sensitive information
from responses that were incorrectly cached. This issue only affected
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-8404)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute python-django-doc –  3:5.2.9-0ubuntu4.3
python3-django –  3:5.2.9-0ubuntu4.3
24.04 LTS noble python-django-doc –  3:4.2.11-1ubuntu1.18
python3-django –  3:4.2.11-1ubuntu1.18
22.04 LTS jammy python-django-doc –  2:3.2.12-2ubuntu1.29
python3-django –  2:3.2.12-2ubuntu1.29
20.04 LTS focal python3-django –  2:2.2.12-1ubuntu0.29+esm10  
18.04 LTS bionic python-django –  1:1.11.11-1ubuntu1.21+esm17  
python-django-common –  1:1.11.11-1ubuntu1.21+esm17  
python3-django –  1:1.11.11-1ubuntu1.21+esm17  
16.04 LTS xenial python-django –  1.8.7-1ubuntu5.15+esm13  
python-django-common –  1.8.7-1ubuntu5.15+esm13  
python3-django –  1.8.7-1ubuntu5.15+esm13  
14.04 LTS trusty python-django –  1.6.11-0ubuntu1.3+esm12  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›