python-django4.2-4.2.28-1.el9
- python-django4.2-4.2.28-1.el9
- Fixes CVE-2025-13473: Username enumeration through timing difference in mod_wsgi authentication handler
- Fixes CVE-2025-14550: Potential denial-of-service vulnerability via repeated headers when using ASGI
- Fixes CVE-2026-1207: Potential SQL injection via raster lookups on PostGIS
- Fixes CVE-2026-1285: Potential denial-of-service vulnerability in django.utils.text.Truncator HTML methods
- Fixes CVE-2026-1287: Potential SQL injection in column aliases via control characters
- Fixes CVE-2026-1312: Potential SQL injection via QuerySet.order_by and FilteredRelation