Django 6.0.2 is out and itโ€™s an important security release ๐Ÿšจ

It fixes:
โ€ข HIGH severity SQL injection issues (FilteredRelation, order_by, PostGIS raster lookups)
โ€ข MODERATE severity DoS issues (ASGI repeated headers, Truncator HTML parsing)
โ€ข a LOW severity timing attack in mod_wsgi auth

djangoproject.com/weblog/2026/

Similar security fixes were also released for Django 5.2.11 and 4.2.28.

If you run Django in production, read the release notes and plan an update ๐Ÿ”’

0

If you have a fediverse account, you can quote this note from your own instance. Search https://fosstodon.org/users/paulox/statuses/116007128624805893 on your instance and quote it. (Note that quoting is not supported in Mastodon.)