Files
buildroot/package/python-django/python-django.hash
Titouan Christophe 63ae2c9f75 package/python-django: security bump to v5.2.13
See the release notes:
https://docs.djangoproject.com/en/5.2/releases/5.2.13/

In addition, update the pypi url to a stable one, which shouldn't change
in each and every release (similar to the url change in commit
60ce218196)

Finally, one hash file has changed because of upstream commit
0ee44c674c

Django 5.2.13 fixes one security issue with severity "moderate",
and four security issues with severity "low":
- CVE-2026-3902:
    An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and
    4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof
    headers by exploiting an ambiguous mapping of two header variants
    (with hyphens or with underscores) to a single version with
    underscores. Earlier, unsupported Django series (such as 5.0.x, 4.1.x,
    and 3.2.x) were not evaluated and may also be affected. Django would
    like to thank Tarek Nakkouch for reporting this issue.
    https://www.cve.org/CVERecord?id=CVE-2026-3902

- CVE-2026-4277:
    An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and
    4.2 before 4.2.30. Add permissions on inline model instances were not
    validated on submission of  forged `POST` data in
    `GenericInlineModelAdmin`. Earlier, unsupported Django series (such as
    5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
    Django would like to thank N05ec@LZU-DSLab for reporting this issue.
    https://www.cve.org/CVERecord?id=CVE-2026-4277

- CVE-2026-4292:
    An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and
    4.2 before 4.2.30. Admin changelist forms using
    `ModelAdmin.list_editable` incorrectly allowed new  instances to be
    created via forged `POST` data. Earlier, unsupported Django series
    (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be
    affected. Django would like to thank Cantina for reporting this issue.
    https://www.cve.org/CVERecord?id=CVE-2026-4292

- CVE-2026-33033:
    An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and
    4.2 before 4.2.30. `MultiPartParser` allows remote attackers to
    degrade performance by submitting multipart uploads with `Content-
    Transfer-Encoding: base64` including excessive whitespace. Earlier,
    unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not
    evaluated and may also be affected. Django would like to thank
    Seokchan Yoon for reporting this issue.
    https://www.cve.org/CVERecord?id=CVE-2026-33033

- CVE-2026-33034:
    An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and
    4.2 before 4.2.30. ASGI requests with a missing or understated
    `Content-Length` header could  bypass the
    `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading  `HttpRequest.body`,
    allowing remote attackers to load an unbounded request body into
    memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and
    3.2.x) were not evaluated and may also be affected. Django would like
    to thank Superior for reporting this issue.
    https://www.cve.org/CVERecord?id=CVE-2026-33034

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-04-30 14:06:43 +02:00

16 lines
1.5 KiB
Plaintext

# md5, sha256 from https://pypi.org/pypi/django/json
md5 4af55cc09a3d1a828259ad0c05330e6b django-5.2.13.tar.gz
sha256 a31589db5188d074c63f0945c3888fad104627dfcc236fb2b97f71f89da33bc4 django-5.2.13.tar.gz
# Locally computed sha256 checksums
sha256 b846415d1b514e9c1dff14a22deb906d794bc546ca6129f950a18cd091e2a669 LICENSE
sha256 a6fa72074c31928128aaa18162204507938b7a9a8b819bd833fa82467441800d django/contrib/gis/measure.py
sha256 570a045a8372b6cd6a00e30ebafe8e3e8dfc0a7fe3d4ef2cc5f16d419eb63aeb django/contrib/gis/gdal/LICENSE
sha256 08bf24b7551238ae325295245425b1caeb9ad0f42f9e2d303c7b353502632045 django/contrib/gis/geos/LICENSE
sha256 d48633adb736dac091477ec2206feebeee88e3e6e486aedb21c584e4b49be0ec django/contrib/admin/static/admin/js/inlines.js
sha256 d4db9ebe6f29f5168eac45ad713f055623ac5d0dcd5ba92da23d650ae012020d django/contrib/admin/static/admin/js/vendor/jquery/LICENSE.txt
sha256 4ee0cbc51370afde358652a0f977972053729ed578b6a42f5e2a037d114f0b39 django/contrib/admin/static/admin/js/vendor/select2/LICENSE.md
sha256 73af2949bff9296cb0f816c3be19a4da4e95adc94c1f924796e8bad3f03f2f29 django/contrib/admin/static/admin/js/vendor/xregexp/LICENSE.txt
sha256 d114faff3488c16c319b3235dc41f90239d3d63d9853733033d8f7535f5c0004 django/contrib/admin/static/admin/img/LICENSE
sha256 54004c4b606964ebc163af16d04607c16e428f8a78a026fecb53f70c09f4a94f django/dispatch/license.txt
sha256 9f37277d682cf06369041e60fb6fda5a85dfcf118d9176489087a3d40293f015 django/utils/archive.py