Jacob Walls

Blog Info The Django weblog
Blog website Link

Django bugfix release issued: 6.1.1

Sept. 2, 2026 » The Django weblog » [Archived Version]

Today we've issued the 6.1.1 bugfix release. The release package and checksums are available from our downloads page, as well as from the Python Package Index. The PGP key ID used for this release is Jacob Walls: 131403F4D16D8DC7

Read More

Django 6.1 released

Aug. 5, 2026 » The Django weblog » [Archived Version]

The Django team is happy to announce the release of Django 6.1. The release notes offer a harmonious mélange of new features and usability improvements. A few highlights are: Model field fetch modes for configuring on-demand fetching behavior Database-level delete options for ForeignKey.on_delete Dictionary-based email settings You can get Django 6.1 from our downloads page or from the Python Package Index. The PGP key ID used for this release is Jacob Walls: 131403F4D16D8DC7 With the r…

Read More

Django 6.1 release candidate 1 released

July 22, 2026 » The Django weblog » [Archived Version]

Django 6.1 release candidate 1 is now available. It represents the final opportunity for you to try out the version that offers a harmonious mélange of new features and usability improvements, before Django 6.1 final is released. The release candidate stage marks the string freeze and the call for translators to submit translations. Provided no major bugs are discovered that can't be solved in the next two weeks, Django 6.1 will be released on or around August 5. Any delays will be communicate…

Read More

Django security releases issued: 6.0.7 and 5.2.16

July 7, 2026 » The Django weblog » [Archived Version]

In accordance with our security release policy, the Django team is issuing releases for Django 6.0.7 and Django 5.2.16. These releases address the security issues detailed below. We encourage all users of Django to upgrade as soon as possible. CVE-2026-48588: Potential exposure of private data via cached Set-Cookie response django.middleware.cache.UpdateCacheMiddleware and django.views.decorators.cache.cache_page avoided caching responses that set a cookie while varying on Cookie only when the …

Read More

Django 6.1 beta 1 released

June 24, 2026 » The Django weblog » [Archived Version]

Django 6.1 beta 1 is now available. It represents the second stage in the 6.1 release cycle and is an opportunity to try out the changes coming in Django 6.1. Django 6.1 offers a harmonious mélange of new features and usability improvements, which you can read about in the in-development 6.1 release notes. Only bugs in new features and regressions from earlier Django versions will be fixed between now and the 6.1 final release. Translations will be updated following the "string freeze", which o…

Read More

Django 6.1 alpha 1 released

May 20, 2026 » The Django weblog » [Archived Version]

Django 6.1 alpha 1 is now available. It represents the first stage in the 6.1 release cycle and is an opportunity to try out the changes coming in Django 6.1. Django 6.1 offers a harmonious mélange of new features and usability improvements, which you can read about in the in-development 6.1 release notes. This alpha milestone marks the feature freeze. The current release schedule calls for a beta release in about a month and a release candidate roughly a month after that. We'll only be able to…

Read More

Django security releases issued: 6.0.4, 5.2.13, and 4.2.30

April 7, 2026 » The Django weblog » [Archived Version]

In accordance with our security release policy, the Django team is issuing releases for Django 6.0.4, Django 5.2.13, and Django 4.2.30. These releases address the security issues detailed below. We encourage all users of Django to upgrade as soon as possible. Django 4.2 has reached the end of extended support Note that with this release, Django 4.2 has reached the end of extended support. All Django 4.2 users are encouraged to upgrade to Django 5.2 or later to continue receiving fixes for secu…

Read More

Recent trends in the work of the Django Security Team

Feb. 4, 2026 » The Django weblog » [Archived Version]

Yesterday, Django issued security releases mitigating six vulnerabilities of varying severity. Django is a secure web framework, and that hasn’t changed. What feels new is the remarkable consistency across the reports we receive now. Almost every report now is a variation on a prior vulnerability. Instead of uncovering new classes of issues, these reports explore how an underlying pattern from a recent advisory might surface in a similar code path or under a slightly different configuration. Th…

Read More

Django security releases issued: 6.0.2, 5.2.11, and 4.2.28

Feb. 3, 2026 » The Django weblog » [Archived Version]

In accordance with our security release policy, the Django team is issuing releases for Django 6.0.2, Django 5.2.11, and Django 4.2.28. These releases address the security issues detailed below. We encourage all users of Django to upgrade as soon as possible. CVE-2025-13473: Username enumeration through timing difference in mod_wsgi authentication handler The django.contrib.auth.handlers.modwsgi.check_password() function for authentication via mod_wsgi allowed remote attackers to enumerate use…

Read More

Django bugfix releases issued: 5.2.10, 6.0.1

Jan. 6, 2026 » The Django weblog » [Archived Version]

Today we've issued the 5.2.10 and 6.0.1 bugfix releases. The release packages and checksums are available from our downloads page, as well as from the Python Package Index. The PGP key ID used for these releases is Jacob Walls: 131403F4D16D8DC7

Read More