Files
packages/lang
Alexandru Ardelean 06eb22a606 python3-django: update to 6.0.4
Update package to 6.0.4.

Security fixes:
- CVE-2026-33033: DoS fix in MultiPartParser -- base64-encoded multipart
  uploads with excessive whitespace could cause repeated memory copying
- CVE-2026-3902: ASGI header spoofing fixed -- headers containing underscores
  are now ignored by ASGIRequest to prevent hyphen/underscore conflation
  attacks
- CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin -- add permissions
  on inline model instances were not validated against forged POST data
- CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable -- changelist
  forms incorrectly allowed new instances to be created via forged POST data
- CVE-2026-33034: DoS via ASGI memory upload limit bypass -- missing or
  understated Content-Length could bypass DATA_UPLOAD_MAX_MEMORY_SIZE

Bug fixes:
- alogin/alogout regression where request.user was not set/cleared if already
  materialized by sync middleware
- RelatedFieldWidgetWrapper regression incorrectly wrapping all widgets in a
  fieldset in admin forms

Signed-off-by: Alexandru Ardelean <alex@shruggie.ro>
2026-04-11 12:56:34 +03:00
..
2026-03-18 09:05:09 +01:00
2026-03-07 01:15:09 +02:00
2026-04-03 22:22:04 +03:00
2026-04-05 15:48:32 +03:00
2026-01-25 07:06:40 +02:00
2026-04-11 12:56:34 +03:00
2025-11-13 19:18:37 +02:00
2026-03-24 08:58:18 +01:00
2026-03-15 09:08:57 +02:00
2025-06-01 10:18:38 +03:00