Update dependency django to v6.0.8 [SECURITY] #13

Merged
jonathan merged 1 commit from renovate/pypi-django-vulnerability into main 2026-08-19 20:41:57 +00:00
Collaborator

This PR contains the following updates:

Package Change Age Confidence
django (changelog) 6.0.76.0.8 age confidence

BIT-django-2026-15830 / CVE-2026-15830 / PYSEC-2026-3717

More information

Details

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
GeoDjango's django.contrib.gis.geos.GEOSGeometry is subject to a potential denial-of-service when parsing deeply nested GEOMETRYCOLLECTION objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the django.contrib.gis.forms.GeometryField form field are also affected.
Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.
Django would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue.

Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

References

This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).


Release Notes

django/django (django)

v6.0.8

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [django](https://github.com/django/django) ([changelog](https://docs.djangoproject.com/en/stable/releases/)) | `6.0.7` → `6.0.8` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/django/6.0.8?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/django/6.0.7/6.0.8?slim=true) | --- ### BIT-django-2026-15830 / [CVE-2026-15830](https://nvd.nist.gov/vuln/detail/CVE-2026-15830) / PYSEC-2026-3717 <details> <summary>More information</summary> #### Details An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue. #### Severity - CVSS Score: 6.9 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X` #### References - [https://www.djangoproject.com/weblog/2026/aug/04/security-releases/](https://www.djangoproject.com/weblog/2026/aug/04/security-releases/) - [https://docs.djangoproject.com/en/dev/releases/security/](https://docs.djangoproject.com/en/dev/releases/security/) - [https://github.com/django/django/commit/6af5da31775417c610dbf9c3f1b5b8333d42daf6](https://github.com/django/django/commit/6af5da31775417c610dbf9c3f1b5b8333d42daf6) - [https://github.com/django/django/commit/9e4a3f186b6b07b483bfd9195ea06734663fcd06](https://github.com/django/django/commit/9e4a3f186b6b07b483bfd9195ea06734663fcd06) - [https://github.com/django/django/commit/ba80833fa656dd09660b97c4429331067db1b080](https://github.com/django/django/commit/ba80833fa656dd09660b97c4429331067db1b080) - [https://github.com/django/django/commit/d2e59b77fe18de318a8272c2a7bbc798d84d1d0d](https://github.com/django/django/commit/d2e59b77fe18de318a8272c2a7bbc798d84d1d0d) - [https://groups.google.com/g/django-announce](https://groups.google.com/g/django-announce) This data is provided by [OSV](https://osv.dev/vulnerability/PYSEC-2026-3717) and the [PyPI Advisory Database](https://github.com/pypa/advisory-database) ([CC-BY 4.0](https://github.com/pypa/advisory-database/blob/main/LICENSE)). </details> --- ### Release Notes <details> <summary>django/django (django)</summary> ### [`v6.0.8`](https://github.com/django/django/compare/6.0.7...6.0.8) [Compare Source](https://github.com/django/django/compare/6.0.7...6.0.8) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODguMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4OC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Update dependency django to v6.0.8 [SECURITY]
All checks were successful
ci / build (push) Successful in 33s
ci / test (push) Successful in 2s
ci / push (push) Successful in 4s
9ca6ed7c2f
jonathan deleted branch renovate/pypi-django-vulnerability 2026-08-19 20:41:57 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
jonathan/min.ie!13
No description provided.