Update dependency django to v6.1.1 [SECURITY] #14

Merged
jonathan merged 1 commit from renovate/pypi-django-vulnerability into main 2026-10-01 06:42:59 +00:00
Collaborator

This PR contains the following updates:

Package Change Age Confidence
django (changelog) 6.1 → 6.1.1 age confidence

Django GeoDjango vulnerable to denial of service through deeply nested geometry collections

BIT-django-2026-15830 / CVE-2026-15830 / GHSA-q238-5cxm-5c9h / PYSEC-2026-3717

More information

Details

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
GeoDjango's django.contrib.gis.geos.GEOSGeometry is subject to a potential denial-of-service when parsing deeply nested GEOMETRYCOLLECTION objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the django.contrib.gis.forms.GeometryField form field are also affected.
Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.
Django would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue.

Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

django/django (django)

v6.1.1

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [django](https://github.com/django/django) ([changelog](https://docs.djangoproject.com/en/stable/releases/)) | `6.1` → `6.1.1` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/django/6.1.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/django/6.1/6.1.1?slim=true) | --- ### Django GeoDjango vulnerable to denial of service through deeply nested geometry collections BIT-django-2026-15830 / [CVE-2026-15830](https://nvd.nist.gov/vuln/detail/CVE-2026-15830) / [GHSA-q238-5cxm-5c9h](https://github.com/advisories/GHSA-q238-5cxm-5c9h) / PYSEC-2026-3717 <details> <summary>More information</summary> #### Details An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue. #### Severity - CVSS Score: 6.9 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N` #### References - [https://nvd.nist.gov/vuln/detail/CVE-2026-15830](https://nvd.nist.gov/vuln/detail/CVE-2026-15830) - [https://github.com/django/django/commit/6af5da31775417c610dbf9c3f1b5b8333d42daf6](https://github.com/django/django/commit/6af5da31775417c610dbf9c3f1b5b8333d42daf6) - [https://github.com/django/django/commit/9e4a3f186b6b07b483bfd9195ea06734663fcd06](https://github.com/django/django/commit/9e4a3f186b6b07b483bfd9195ea06734663fcd06) - [https://github.com/django/django/commit/ba80833fa656dd09660b97c4429331067db1b080](https://github.com/django/django/commit/ba80833fa656dd09660b97c4429331067db1b080) - [https://github.com/django/django/commit/d2e59b77fe18de318a8272c2a7bbc798d84d1d0d](https://github.com/django/django/commit/d2e59b77fe18de318a8272c2a7bbc798d84d1d0d) - [https://docs.djangoproject.com/en/dev/releases/security](https://docs.djangoproject.com/en/dev/releases/security) - [https://github.com/django/django](https://github.com/django/django) - [https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2026-3717.yaml](https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2026-3717.yaml) - [https://groups.google.com/g/django-announce](https://groups.google.com/g/django-announce) - [https://www.djangoproject.com/weblog/2026/aug/04/security-releases](https://www.djangoproject.com/weblog/2026/aug/04/security-releases) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-q238-5cxm-5c9h) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>django/django (django)</summary> ### [`v6.1.1`](https://github.com/django/django/compare/6.1...6.1.1) [Compare Source](https://github.com/django/django/compare/6.1...6.1.1) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMjUuMiIsInVwZGF0ZWRJblZlciI6IjQ0LjEyNS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Update dependency django to v6.1.1 [SECURITY]
All checks were successful
ci / build (push) Successful in 1m16s
ci / test (push) Successful in 1s
ci / push (push) Successful in 6s
7def1c74d9
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
jonathan/min.ie!14
No description provided.