Django 6.0.2 is out and itโs an important security release ๐จ
It fixes:
โข HIGH severity SQL injection issues (FilteredRelation, order_by, PostGIS raster lookups)
โข MODERATE severity DoS issues (ASGI repeated headers, Truncator HTML parsing)
โข a LOW severity timing attack in mod_wsgi auth
https://www.djangoproject.com/weblog/2026/feb/03/security-releases/
Similar security fixes were also released for Django 5.2.11 and 4.2.28.
If you run Django in production, read the release notes and plan an update ๐
