@@ -16,7 +16,7 @@ The ``django.contrib.auth.handlers.modwsgi.check_password()`` function for
1616allowed remote attackers to enumerate users via a timing attack.
1717
1818This issue has severity "low" according to the :ref:`Django security policy
19- <security-disclosure >`.
19+ <severity-levels >`.
2020
2121CVE-2025-14550: Potential denial-of-service vulnerability via repeated headers when using ASGI
2222==============================================================================================
@@ -28,7 +28,7 @@ repeated string concatenation while combining repeated headers, which
2828produced super-linear computation resulting in service degradation or outage.
2929
3030This issue has severity "moderate" according to the :ref:`Django security
31- policy <security-disclosure >`.
31+ policy <severity-levels >`.
3232
3333CVE-2026-1207: Potential SQL injection via raster lookups on PostGIS
3434====================================================================
4040As a reminder, all untrusted user input should be validated before use.
4141
4242This issue has severity "high" according to the :ref:`Django security policy
43- <security-disclosure >`.
43+ <severity-levels >`.
4444
4545CVE-2026-1285: Potential denial-of-service vulnerability in ``django.utils.text.Truncator`` HTML methods
4646========================================================================================================
@@ -52,7 +52,7 @@ denial-of-service attack via certain inputs with a large number of unmatched
5252HTML end tags, which could cause quadratic time complexity during HTML parsing.
5353
5454This issue has severity "moderate" according to the :ref:`Django security
55- policy <security-disclosure >`.
55+ policy <severity-levels >`.
5656
5757CVE-2026-1287: Potential SQL injection in column aliases via control characters
5858===============================================================================
@@ -65,7 +65,7 @@ expansion, as the ``**kwargs`` passed to :meth:`.QuerySet.annotate`,
6565:meth:`~.QuerySet.alias`.
6666
6767This issue has severity "high" according to the :ref:`Django security policy
68- <security-disclosure >`.
68+ <severity-levels >`.
6969
7070CVE-2026-1312: Potential SQL injection via ``QuerySet.order_by`` and ``FilteredRelation``
7171=========================================================================================
@@ -75,4 +75,4 @@ containing periods when the same alias was, using a suitably crafted
7575dictionary, with dictionary expansion, used in :class:`.FilteredRelation`.
7676
7777This issue has severity "high" according to the :ref:`Django security policy
78- <security-disclosure >`.
78+ <severity-levels >`.
0 commit comments