Django 5.x — End of Life

Active Critical risk
EOL: Apr 30, 2028in 600d3 releases in this series34 CVEs

Django 5.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
5.2LTSApr 2, 2025Dec 3, 2025Apr 30, 20285.2.17Active
5.1Aug 7, 2024Apr 2, 2025Dec 3, 20255.1.15EOL
5.0Dec 4, 2023Aug 7, 2024Apr 2, 20255.0.14EOL

CVEs affecting Django 5.x (34)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-15920MEDIUM6.10.39%5.2An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field(…Aug 4, 2026
CVE-2026-15830MEDIUM5.31.25%5.0An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome…Aug 4, 2026
CVE-2026-15830MEDIUM5.31.25%5.2An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome…Aug 4, 2026
CVE-2026-15830MEDIUM5.31.25%5.1An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome…Aug 4, 2026
CVE-2026-15337MEDIUM5.31.02%5.2An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()…Aug 4, 2026
CVE-2026-15337MEDIUM5.31.02%5.0An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()…Aug 4, 2026
CVE-2026-15337MEDIUM5.31.02%5.1An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()…Aug 4, 2026
CVE-2026-15307HIGH8.80.89%5.1An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse…Aug 4, 2026
CVE-2026-15307HIGH8.80.89%5.0An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse…Aug 4, 2026
CVE-2026-15307HIGH8.80.89%5.2An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse…Aug 4, 2026
CVE-2026-53878MEDIUM6.10.32%5.2An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlin…Jul 7, 2026
CVE-2026-53877MEDIUM4.80.43%5.2An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-read…Jul 7, 2026
CVE-2026-48588LOW3.10.42%5.2An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()`…Jul 7, 2026
CVE-2026-8404LOW3.10.28%5.2An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware…Jun 3, 2026
CVE-2026-7666LOW3.10.15%5.2An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` …Jun 3, 2026
CVE-2026-6873LOW3.10.24%5.2An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in…Jun 3, 2026
CVE-2026-48587LOW3.10.36%5.2An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Djan…Jun 3, 2026
CVE-2026-35193LOW3.10.37%5.2An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware…Jun 3, 2026
CVE-2026-6907MEDIUM4.30.35%5.2An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erron…May 5, 2026
CVE-2026-5766MEDIUM5.30.42%5.2An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-…May 5, 2026
CVE-2026-35192MEDIUM6.50.54%5.2An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session …May 5, 2026
CVE-2026-4292LOW2.70.29%5.2An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `Mod…Apr 7, 2026
CVE-2026-4277CRITICAL9.80.45%5.2An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model i…Apr 7, 2026
CVE-2026-3902HIGH7.50.43%5.2An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote att…Apr 7, 2026
CVE-2026-33034HIGH7.50.76%5.2An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or u…Apr 7, 2026
CVE-2026-33033MEDIUM6.50.87%5.2An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote a…Apr 7, 2026
CVE-2026-25674LOW3.70.34%5.2An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system sto…Mar 3, 2026
CVE-2026-25673HIGH7.50.73%5.2An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django …Mar 3, 2026
CVE-2026-1312MEDIUM5.40.83%5.2An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject…Feb 3, 2026
CVE-2026-1287MEDIUM5.40.78%5.2An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to …Feb 3, 2026
CVE-2026-1285HIGH7.51.03%5.2An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.char…Feb 3, 2026
CVE-2026-1207MEDIUM5.412.97%5.2An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField``…Feb 3, 2026
CVE-2025-14550HIGH7.51.03%5.2An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote att…Feb 3, 2026
CVE-2025-13473MEDIUM5.30.74%5.2An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers…Feb 3, 2026

Django 5.x will reach end of life — migrate to Django 6.x

Django 6.x is the next major release. Plan your upgrade before Django 5.x stops receiving security patches.

See Django 6.x

Frequently asked questions

Is Django 5 end of life?

Partially. Some Django 5.x releases have reached EOL. Check the version table above for the exact status of each sub-release.

What CVEs affect Django 5?

There are 34 CVEs tracked for Django 5.x, including 1 critical severity issue. See the full list above with CVSS and EPSS scores.

What is the latest Django 5 version?

The latest Django 5.x patch release is 5.2.17, released on August 4, 2026. Always run the latest patch to benefit from all security fixes.

How to migrate from Django 5 to Django 6?

To migrate from Django 5 to Django 6: (1) review the official Django 6 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Django 5 in production?

Django 5 is still supported and safe for production use until April 30, 2028. Ensure you are running the latest patch version (5.2.17) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA