Django 5.x — End of Life
Active Critical riskDjango 5.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 5.2LTS | Apr 2, 2025 | Dec 3, 2025 | Apr 30, 2028 | 5.2.17 | Active | |
| 5.1 | Aug 7, 2024 | Apr 2, 2025 | Dec 3, 2025 | 5.1.15 | EOL | |
| 5.0 | Dec 4, 2023 | Aug 7, 2024 | Apr 2, 2025 | 5.0.14 | EOL |
CVEs affecting Django 5.x (34)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-15920 | MEDIUM | 6.1 | 0.39% | — | 5.2 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field(… | Aug 4, 2026 |
| CVE-2026-15830 | MEDIUM | 5.3 | 1.25% | — | 5.0 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome… | Aug 4, 2026 |
| CVE-2026-15830 | MEDIUM | 5.3 | 1.25% | — | 5.2 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome… | Aug 4, 2026 |
| CVE-2026-15830 | MEDIUM | 5.3 | 1.25% | — | 5.1 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome… | Aug 4, 2026 |
| CVE-2026-15337 | MEDIUM | 5.3 | 1.02% | — | 5.2 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()… | Aug 4, 2026 |
| CVE-2026-15337 | MEDIUM | 5.3 | 1.02% | — | 5.0 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()… | Aug 4, 2026 |
| CVE-2026-15337 | MEDIUM | 5.3 | 1.02% | — | 5.1 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()… | Aug 4, 2026 |
| CVE-2026-15307 | HIGH | 8.8 | 0.89% | — | 5.1 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse… | Aug 4, 2026 |
| CVE-2026-15307 | HIGH | 8.8 | 0.89% | — | 5.0 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse… | Aug 4, 2026 |
| CVE-2026-15307 | HIGH | 8.8 | 0.89% | — | 5.2 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse… | Aug 4, 2026 |
| CVE-2026-53878 | MEDIUM | 6.1 | 0.32% | — | 5.2 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlin… | Jul 7, 2026 |
| CVE-2026-53877 | MEDIUM | 4.8 | 0.43% | — | 5.2 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-read… | Jul 7, 2026 |
| CVE-2026-48588 | LOW | 3.1 | 0.42% | — | 5.2 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()`… | Jul 7, 2026 |
| CVE-2026-8404 | LOW | 3.1 | 0.28% | — | 5.2 | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware… | Jun 3, 2026 |
| CVE-2026-7666 | LOW | 3.1 | 0.15% | — | 5.2 | An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` … | Jun 3, 2026 |
| CVE-2026-6873 | LOW | 3.1 | 0.24% | — | 5.2 | An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in… | Jun 3, 2026 |
| CVE-2026-48587 | LOW | 3.1 | 0.36% | — | 5.2 | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Djan… | Jun 3, 2026 |
| CVE-2026-35193 | LOW | 3.1 | 0.37% | — | 5.2 | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware… | Jun 3, 2026 |
| CVE-2026-6907 | MEDIUM | 4.3 | 0.35% | — | 5.2 | An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erron… | May 5, 2026 |
| CVE-2026-5766 | MEDIUM | 5.3 | 0.42% | — | 5.2 | An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-… | May 5, 2026 |
| CVE-2026-35192 | MEDIUM | 6.5 | 0.54% | — | 5.2 | An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session … | May 5, 2026 |
| CVE-2026-4292 | LOW | 2.7 | 0.29% | — | 5.2 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `Mod… | Apr 7, 2026 |
| CVE-2026-4277 | CRITICAL | 9.8 | 0.45% | — | 5.2 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model i… | Apr 7, 2026 |
| CVE-2026-3902 | HIGH | 7.5 | 0.43% | — | 5.2 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote att… | Apr 7, 2026 |
| CVE-2026-33034 | HIGH | 7.5 | 0.76% | — | 5.2 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or u… | Apr 7, 2026 |
| CVE-2026-33033 | MEDIUM | 6.5 | 0.87% | — | 5.2 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote a… | Apr 7, 2026 |
| CVE-2026-25674 | LOW | 3.7 | 0.34% | — | 5.2 | An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system sto… | Mar 3, 2026 |
| CVE-2026-25673 | HIGH | 7.5 | 0.73% | — | 5.2 | An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django … | Mar 3, 2026 |
| CVE-2026-1312 | MEDIUM | 5.4 | 0.83% | — | 5.2 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject… | Feb 3, 2026 |
| CVE-2026-1287 | MEDIUM | 5.4 | 0.78% | — | 5.2 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to … | Feb 3, 2026 |
| CVE-2026-1285 | HIGH | 7.5 | 1.03% | — | 5.2 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.char… | Feb 3, 2026 |
| CVE-2026-1207 | MEDIUM | 5.4 | 12.97% | — | 5.2 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField``… | Feb 3, 2026 |
| CVE-2025-14550 | HIGH | 7.5 | 1.03% | — | 5.2 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote att… | Feb 3, 2026 |
| CVE-2025-13473 | MEDIUM | 5.3 | 0.74% | — | 5.2 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers… | Feb 3, 2026 |
Django 5.x will reach end of life — migrate to Django 6.x
Django 6.x is the next major release. Plan your upgrade before Django 5.x stops receiving security patches.
Frequently asked questions
Is Django 5 end of life?
Partially. Some Django 5.x releases have reached EOL. Check the version table above for the exact status of each sub-release.
What CVEs affect Django 5?
There are 34 CVEs tracked for Django 5.x, including 1 critical severity issue. See the full list above with CVSS and EPSS scores.
What is the latest Django 5 version?
The latest Django 5.x patch release is 5.2.17, released on August 4, 2026. Always run the latest patch to benefit from all security fixes.
How to migrate from Django 5 to Django 6?
To migrate from Django 5 to Django 6: (1) review the official Django 6 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Django 5 in production?
Django 5 is still supported and safe for production use until April 30, 2028. Ensure you are running the latest patch version (5.2.17) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
