Django 2.x — End of Life

EOL High risk
EOL: Apr 11, 20223 releases in this series3 CVEs

Django 2.x reached end of life on Apr 11, 2022, 1640 days ago, and no longer receives security fixes. The most recent release in this series is 2.2.28. 3 CVEs are tracked for this series. 3 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is Django 3. See Django 3 →

Django 2.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
2.2LTSApr 1, 2019Dec 2, 2019Apr 11, 20222.2.28EOL
2.1Aug 1, 2018Apr 1, 2019Dec 2, 20192.1.15EOL
2.0Dec 2, 2017Aug 1, 2018Apr 1, 20192.0.13EOL

CVEs affecting Django 2.x (9)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-15830MEDIUM5.30.76%—2.0An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome…Aug 4, 2026
CVE-2026-15830MEDIUM5.30.76%—2.2An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome…Aug 4, 2026
CVE-2026-15830MEDIUM5.30.76%—2.1An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome…Aug 4, 2026
CVE-2026-15337MEDIUM5.30.59%—2.0An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()…Aug 4, 2026
CVE-2026-15337MEDIUM5.30.59%—2.2An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()…Aug 4, 2026
CVE-2026-15337MEDIUM5.30.59%—2.1An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()…Aug 4, 2026
CVE-2026-15307HIGH8.81.09%—2.2An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse…Aug 4, 2026
CVE-2026-15307HIGH8.81.09%—2.1An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse…Aug 4, 2026
CVE-2026-15307HIGH8.81.09%—2.0An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse…Aug 4, 2026

Django 2.x is EOL — migrate to Django 3.x

Django 3.x is the next major release. Plan your upgrade before Django 2.x stops receiving security patches.

See Django 3.x

Add a Django 2 EOL badge to your README

Show your users which Django version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

Django 2 EOL status
[![Django 2 EOL status](https://eolcanary.com/badge/django/2.svg)](https://eolcanary.com/explore/django/2)

Frequently asked questions

Is Django 2 end of life?

Yes. All Django 2.x releases have reached end of life and no longer receive security patches. There are 3 known CVEs affecting Django 2.x. Migrate to Django 3.x as soon as possible.

What CVEs affect Django 2?

There are 3 CVEs tracked for Django 2.x. See the full list above with CVSS and EPSS scores.

What is the latest Django 2 version?

The latest Django 2.x patch release is 2.2.28, released on April 11, 2022. Always run the latest patch to benefit from all security fixes.

How to migrate from Django 2 to Django 3?

To migrate from Django 2 to Django 3: (1) review the official Django 3 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Django 2 in production?

No. Django 2 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA