This release includes 4 security fixes for security teams reviewing exposed deployments.
Published 1mo
Productivity & Wikis
✓ No known CVEs patched
This release patches 4 known CVEs
Topics
cms
django
python
wagtail
Affected surfaces
auth
rbac
Summary
AI summaryCVE-2026-54259 addresses improper restriction handling on Documents and Images endpoints.
Full changelog
- CVE-2026-54259: Improper restriction handling on Documents and Images chosen endpoints (Harsh Akshit, Dan Braghis)
- CVE-2026-54260: Denial of service via unbounded filter specs in the image preview (0x1saac, Dan Braghis)
- CVE-2026-54261: Improper permission handling in image preview (Harsh Akshit, 0x1saac, Dan Braghis)
- CVE-2026-54262: Pages translations can be created without page permissions when using simple_translation (Devansh Bordia, alanturing881, Dan Braghis)
Security Fixes
- CVE-2026-54259: Improper restriction handling on Documents and Images chosen endpoints
- CVE-2026-54260: Denial of service via unbounded filter specs in the image preview
- CVE-2026-54261: Improper permission handling in image preview
- CVE-2026-54262: Pages translations can be created without page permissions when using simple_translation
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Wagtail
Django content management system focused on flexibility and user experience.
Related context
Related tools
Beta — feedback welcome: [email protected]