Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS / 20.04 LTS / 22.04 LTS / 24.04 LTS / 26.04 LTS : Django vulnerabilities (USN-8848-1)

medium Nessus Plugin ID 362565

Synopsis

The remote Ubuntu host is missing a security update.

Description

The remote Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS / 20.04 LTS / 22.04 LTS / 24.04 LTS / 26.04 LTS host has packages installed that are affected by a vulnerability as referenced in the USN-8848-1 advisory.

Bence Nagy discovered that GeoDjango in Django incorrectly handled spatial lookups when processing untrusted input. A remote attacker could possibly use this issue to make outbound network requests, write arbitrary files, or execute arbitrary code. This issue was only addressed in Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-15307)

Ahmad Sadeddin discovered that Django UpdateCacheMiddleware incorrectly cached requests where the Vary header contained an asterisk. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-6907)

Ahmed Badawe discovered that Django did not properly parse Cache-Control response directives case- insensitively under certain circumstances. A remote attacker could possibly use this issue to view sensitive information from responses that were incorrectly cached. This issue only affected

Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-8404)

Tenable has extracted the preceding description block directly from the Ubuntu security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected python-django, python-django-common and / or python3-django packages.

See Also

https://ubuntu.com/security/notices/USN-8848-1

Plugin Details

Severity: Medium

ID: 362565

File Name: ubuntu_USN-8848-1.nasl

Version: 1.2

Type: Local

Agent: unix

Published: 10/2/2026

Updated: 10/2/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Vulnerability Information

CPE: cpe:/o:canonical:ubuntu_linux:14.04:-:lts, cpe:/o:canonical:ubuntu_linux:16.04:-:lts, cpe:/o:canonical:ubuntu_linux:18.04:-:lts, cpe:/o:canonical:ubuntu_linux:20.04:-:lts, cpe:/o:canonical:ubuntu_linux:22.04:-:lts, cpe:/o:canonical:ubuntu_linux:24.04:-:lts, cpe:/o:canonical:ubuntu_linux:26.04:-:lts, p-cpe:/a:canonical:ubuntu_linux:python-django-common, p-cpe:/a:canonical:ubuntu_linux:python-django, p-cpe:/a:canonical:ubuntu_linux:python3-django

Required KB Items: Host/cpu, Host/Ubuntu, Host/Ubuntu/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 9/30/2026

Vulnerability Publication Date: 9/30/2026

Reference Information

USN: 8848-1