File _patchinfo of Package patchinfo.41924
<patchinfo incident="41924"> <issue tracker="bnc" id="1254437">VUL-0: CVE-2025-64460,CVE-2025-13372: python-Django: Algorithmic complexity in `django.core.serializers.xml_serializer.getInnerText()` allows a remote attacker to cause a potential denial-of-service attack triggering CPU and memory exhaustion</issue> <issue tracker="cve" id="2025-13372"/> <issue tracker="cve" id="2025-64460"/> <packager>mcalabkova</packager> <rating>important</rating> <category>security</category> <summary>Security update for python-Django</summary> <description>This update for python-Django fixes the following issues: - CVE-2025-13372: Fixed SQL Injection in FilteredRelation (bsc#1254437) - CVE-2025-64460: Fixed denial of service via specially crafted XML input in django.core.serializers.xml_serializer.getInnerText() (bsc#1254437) </description> </patchinfo>