Aggregator

USN-8232-1: Django vulnerabilities

4 days 5 hours ago
It was discovered that Django did not vary cached response headers on cookies when sessions were not modified while SESSION_SAVE_EVERY_REQUEST was enabled. A remote attacker could possibly use this issue to steal a user's session. (CVE-2026-35192) Kyle Agronick and Jacob Walls discovered that Django incorrectly handled ASGI requests with missing or understated Content-Length header values. A remote attacker could possibly use this issue to cause Django to use excessive resources, leading to a denial of service. (CVE-2026-5766) Ahmad Sadeddin discovered that Django UpdateCacheMiddleware incorrectly cached requests where the Vary header contained an asterisk. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-6907)

opencryptoki-3.26.0-3.fc45

4 days 11 hours ago
FEDORA-2026-d63e3968e8 Packages in this update:
  • opencryptoki-3.26.0-3.fc45
Update description:

Automatic update for opencryptoki-3.26.0-3.fc45.

Changelog * Tue May 5 2026 Than Ngo <than@redhat.com> - 3.26.0-3 - Fix rhbz#2432016: CVE-2026-23893, Privilege Escalation or Data Exposure via Symlink Following