Django 6.x — End of Life
Active Critical risk EOL: Dec 31, 2027in 506d2 releases in this series24 CVEs
Django 6.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 6.1 | Aug 5, 2026 | Apr 30, 2027 | Dec 31, 2027 | 6.1 | Active | |
| 6.0 | Dec 3, 2025 | Aug 4, 2026 | Apr 30, 2027 | 6.0.8 | Active |
CVEs affecting Django 6.x (24)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-53878 | MEDIUM | 6.1 | 0.20% | — | 6.0 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlin… | Jul 7, 2026 |
| CVE-2026-53877 | MEDIUM | 4.8 | 0.28% | — | 6.0 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-read… | Jul 7, 2026 |
| CVE-2026-48588 | LOW | 3.1 | 0.36% | — | 6.0 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()`… | Jul 7, 2026 |
| CVE-2026-8404 | LOW | 3.1 | 0.28% | — | 6.0 | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware… | Jun 3, 2026 |
| CVE-2026-7666 | LOW | 3.1 | 0.15% | — | 6.0 | An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` … | Jun 3, 2026 |
| CVE-2026-6873 | LOW | 3.1 | 0.24% | — | 6.0 | An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in… | Jun 3, 2026 |
| CVE-2026-48587 | LOW | 3.1 | 0.35% | — | 6.0 | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Djan… | Jun 3, 2026 |
| CVE-2026-35193 | LOW | 3.1 | 0.35% | — | 6.0 | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware… | Jun 3, 2026 |
| CVE-2026-6907 | MEDIUM | 4.3 | 0.35% | — | 6.0 | An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erron… | May 5, 2026 |
| CVE-2026-5766 | MEDIUM | 5.3 | 0.42% | — | 6.0 | An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-… | May 5, 2026 |
| CVE-2026-35192 | MEDIUM | 6.5 | 0.54% | — | 6.0 | An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session … | May 5, 2026 |
| CVE-2026-4292 | LOW | 2.7 | 0.29% | — | 6.0 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `Mod… | Apr 7, 2026 |
| CVE-2026-4277 | CRITICAL | 9.8 | 0.45% | — | 6.0 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model i… | Apr 7, 2026 |
| CVE-2026-3902 | HIGH | 7.5 | 0.43% | — | 6.0 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote att… | Apr 7, 2026 |
| CVE-2026-33034 | HIGH | 7.5 | 0.76% | — | 6.0 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or u… | Apr 7, 2026 |
| CVE-2026-33033 | MEDIUM | 6.5 | 0.87% | — | 6.0 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote a… | Apr 7, 2026 |
| CVE-2026-25674 | LOW | 3.7 | 0.34% | — | 6.0 | An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system sto… | Mar 3, 2026 |
| CVE-2026-25673 | HIGH | 7.5 | 0.73% | — | 6.0 | An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django … | Mar 3, 2026 |
| CVE-2026-1312 | MEDIUM | 5.4 | 0.80% | — | 6.0 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject… | Feb 3, 2026 |
| CVE-2026-1287 | MEDIUM | 5.4 | 0.75% | — | 6.0 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to … | Feb 3, 2026 |
| CVE-2026-1285 | HIGH | 7.5 | 0.99% | — | 6.0 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.char… | Feb 3, 2026 |
| CVE-2026-1207 | MEDIUM | 5.4 | 12.97% | — | 6.0 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField``… | Feb 3, 2026 |
| CVE-2025-14550 | HIGH | 7.5 | 0.99% | — | 6.0 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote att… | Feb 3, 2026 |
| CVE-2025-13473 | MEDIUM | 5.3 | 0.71% | — | 6.0 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers… | Feb 3, 2026 |
Frequently asked questions
Is Django 6 end of life?
No. Django 6.x is still supported until December 31, 2027. It continues to receive security patches and bug fixes.
What CVEs affect Django 6?
There are 24 CVEs tracked for Django 6.x, including 1 critical severity issue. See the full list above with CVSS and EPSS scores.
What is the latest Django 6 version?
The latest Django 6.x patch release is 6.1, released on August 5, 2026. Always run the latest patch to benefit from all security fixes.
When was Django 6 first released?
Django 6.0 was initially released on August 5, 2026. See the full version timeline in the table above.
Is it safe to run Django 6 in production?
Django 6 is still supported and safe for production use until December 31, 2027. Ensure you are running the latest patch version (6.1) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
