Django 6.x — End of Life

Active Critical risk
EOL: Dec 31, 2027in 450d2 releases in this series28 CVEs

Django 6.x is still supported until Dec 31, 2027, in 450 days. The most recent release in this series is 6.1.2. 28 CVEs are tracked for this series, including 1 critical.

Django 6.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
6.1Aug 5, 2026Apr 30, 2027Dec 31, 20276.1.2Active
6.0Dec 3, 2025Aug 4, 2026Apr 30, 20276.0.9Active

CVEs affecting Django 6.x (28)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-15920MEDIUM6.10.35%—6.0An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field(…Aug 4, 2026
CVE-2026-15830MEDIUM5.30.76%—6.0An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome…Aug 4, 2026
CVE-2026-15337MEDIUM5.30.59%—6.0An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()…Aug 4, 2026
CVE-2026-15307HIGH8.81.09%—6.0An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse…Aug 4, 2026
CVE-2026-53878MEDIUM6.10.32%—6.0An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlin…Jul 7, 2026
CVE-2026-53877MEDIUM4.80.43%—6.0An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-read…Jul 7, 2026
CVE-2026-48588LOW3.10.42%—6.0An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()`…Jul 7, 2026
CVE-2026-8404LOW3.10.42%—6.0An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware…Jun 3, 2026
CVE-2026-7666LOW3.10.20%—6.0An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` …Jun 3, 2026
CVE-2026-6873LOW3.10.28%—6.0An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in…Jun 3, 2026
CVE-2026-48587LOW3.10.42%—6.0An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Djan…Jun 3, 2026
CVE-2026-35193LOW3.10.43%—6.0An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware…Jun 3, 2026
CVE-2026-6907MEDIUM4.30.43%—6.0An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erron…May 5, 2026
CVE-2026-5766MEDIUM5.30.51%—6.0An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-…May 5, 2026
CVE-2026-35192MEDIUM6.50.68%—6.0An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session …May 5, 2026
CVE-2026-4292LOW2.70.36%—6.0An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `Mod…Apr 7, 2026
CVE-2026-4277CRITICAL9.80.60%—6.0An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model i…Apr 7, 2026
CVE-2026-3902HIGH7.50.54%—6.0An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote att…Apr 7, 2026
CVE-2026-33034HIGH7.50.85%—6.0An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or u…Apr 7, 2026
CVE-2026-33033MEDIUM6.50.88%—6.0An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote a…Apr 7, 2026
CVE-2026-25674LOW3.70.33%—6.0An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system sto…Mar 3, 2026
CVE-2026-25673HIGH7.51.14%—6.0An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django …Mar 3, 2026
CVE-2026-1312MEDIUM5.40.91%—6.0An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject…Feb 3, 2026
CVE-2026-1287MEDIUM5.40.85%—6.0An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to …Feb 3, 2026
CVE-2026-1285HIGH7.51.12%—6.0An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.char…Feb 3, 2026
CVE-2026-1207MEDIUM5.412.81%—6.0An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField``…Feb 3, 2026
CVE-2025-14550HIGH7.51.12%—6.0An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote att…Feb 3, 2026
CVE-2025-13473MEDIUM5.30.81%—6.0An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers…Feb 3, 2026

Add a Django 6 EOL badge to your README

Show your users which Django version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

Django 6 EOL status
[![Django 6 EOL status](https://eolcanary.com/badge/django/6.svg)](https://eolcanary.com/explore/django/6)

Frequently asked questions

Is Django 6 end of life?

No. Django 6.x is still supported until December 31, 2027. It continues to receive security patches and bug fixes.

What CVEs affect Django 6?

There are 28 CVEs tracked for Django 6.x, including 1 critical severity issue. See the full list above with CVSS and EPSS scores.

What is the latest Django 6 version?

The latest Django 6.x patch release is 6.1.2, released on October 6, 2026. Always run the latest patch to benefit from all security fixes.

When was Django 6 first released?

Django 6.0 was released on December 3, 2025. See the full version timeline in the table above.

Is it safe to run Django 6 in production?

Yes, Django 6 is still supported. Support ends on December 31, 2027. Make sure you run the latest patch (6.1.2) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA