File _patchinfo of Package patchinfo.41924

<patchinfo incident="41924">
  <issue tracker="bnc" id="1254437">VUL-0: CVE-2025-64460,CVE-2025-13372: python-Django: Algorithmic complexity in `django.core.serializers.xml_serializer.getInnerText()` allows a remote attacker to cause a potential denial-of-service attack triggering CPU and memory exhaustion</issue>
  <issue tracker="cve" id="2025-13372"/>
  <issue tracker="cve" id="2025-64460"/>
  <packager>mcalabkova</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for python-Django</summary>
  <description>This update for python-Django fixes the following issues:

- CVE-2025-13372: Fixed SQL Injection in FilteredRelation (bsc#1254437)
- CVE-2025-64460: Fixed denial of service via specially crafted XML input in 
  django.core.serializers.xml_serializer.getInnerText() (bsc#1254437)
</description>
</patchinfo>
openSUSE Build Service is sponsored by