| in blog | Django News |
|---|---|
| published date | 2026-10-09 |
| original entry | Issue 358: Django 6.1.2, 6.0.9, and 5.2.18 Security Releases and Djangonaut Space Session 7 |
Four CVEs fixed: denial-of-service risks in language-code lookups and HTTP header parsing, spatial lookups that could make GDAL fetch external rasters, and model formsets with editable primary keys that forged POST data could use to delete or create instances. Raster bytes passed to spatial lookups must now be wrapped in GDALRaster, a backward-incompatible change, so upgrade and check your GIS code.
Djangonaut Space Session 7 runs October 12 to December 6 with its biggest cohort yet: 28 Djangonauts picked from 92 applicants, across eight teams working on Django core, accessibility, Django Debug Toolbar, djangoCMS, and the Django Girls+ website, plus two Python projects, BeeWare and Render Engine.
Django no longer takes new security reports through HackerOne. Existing HackerOne reports stay open with the Security Team, and new issues should go to [email protected] as described in the security policy.
Last-minute lazy-import release blockers earned 3.15 a surprise third release candidate, pushing 3.15.0 final to October 9. Maintainers should test and publish 3.15 wheels now; release candidate wheels will work with the final release.
Agent-friendly documentation for your Wagtail tasks.
A weekly, sometimes daily, flood of low-effort PRs (one fix came "tested" with a screenshot that wasn't even the Wagtail UI) has Wagtail pulling core out of Google Summer of Code 2027. It may still mentor on simpler projects like the user guide and Made with Wagtail, so register interest via the form rather than opening PRs, since nothing is confirmed until March 2027.
Today, "Updates to Django" is presented by Raffaella from Djangonaut Space! 🚀
Last week we had 13 pull requests merged into Django by 11 different contributors - including 2 first-time contributors! Congratulations to Juliana Nicacio and Max Azatian for having their first commits merged into Django - welcome on board!
News in Django:
UUID4 function persisted uppercase values on Oracle. Any data already created using this function on Oracle should be migrated to lowercase so that it can be queried correctly (#37376).TupleIn) when an F() expression was used as the left-hand side (#37291).Adam Johnson follows his security.txt post with the files that let iOS and Android apps open your site's links (Universal Links and App Links) and use its saved passwords and passkeys. He covers the JSON content types, keeping /admin/ in the browser, caching, tests, and how to check what Apple and Google actually fetch.
A short post on attending this year's event and giving one of the talks.
The 8 questions to ask any Django-based employer before joining their engineering team.
Stein Ove Helset builds a small idea board and shows where AI earns its keep: first-draft templates and tests, plus reviewing a working vote view instead of being told to "make this better," which surfaces the race condition in votes += 1 that an F() expression fixes. His rule: treat AI code like a random Stack Overflow answer you are now responsible for, and never paste in real secrets.
Instead of a server per side project, give each one its own virtualenv and a Gunicorn process on its own local port (8001, 8002, and so on) kept alive by Supervisor, then let Nginx route by server_name. Each project can run a different Django version and database, and adding another is mostly a matter of repeating the steps.
Sponsor this newsletter to reach an active community of Python and Django developers.
Natalia cleared the untriaged queue (10 tickets), reviewed the Sphinx compatibility changes and fixed related doc references, and reviewed support for Address objects as email addresses. On the security side, she reviewed a confirmed vulnerability and helped Jacob send pre-notifications for the October 6 release.
A heads-down week closing release blockers for 6.1.2: Jacob fixed UUID4() persisting uppercase hex on Oracle, filed tickets for JSONField __in lookups on primitives and iterating F("pk") hanging, repaired failing MySQL jobs on Jenkins, and sent the security pre-notifications.
From a holiday in Turkey, Sarah still opened PRs to allow multiline template tags and fix the tokenization of raw template blocks, reviewed the PR dropping GDAL 3.3 and 3.4, and worked on two security issues. Her following week was properly off: swimming and Turkish food.
The complete recording is up of this recent full day conference of Django goodness.
Dr. Chuck Severance follows data from an HTML form to the database and back in this 25-minute course lecture: GET versus POST, CSRF protection, templates, and class-based and generic views, with the object-oriented inheritance behind them. It wraps up the guided tutorials before his students move on to more independent Django work.
An 11-minute walkthrough centered on version 3 of the Wagtail API, which can now publish, update, and organize content for automated and AI-agent workflows. It also covers custom base page models, the new permission policy registry, Django 6.1 support, and accessibility and image format improvements.
A five-minute look at Wagtail's experimental MCP server: an agent built into the CMS, running DeepSeek V4 Flash with 50+ tools and no instructions on how to use them, doing content operations.
A new junior developer opening at Softechassociate joins Proxify AB's two senior roles, one Python backend and one React/Node fullstack.
Junior Developer at Softechassociate 🆕
Senior Backend Developer (Python) at Proxify AB
Senior Fullstack Developer (React.js / Node.js) at Proxify AB
Django performance benchmark profiler.
Point it at your lockfile and it asks PyPI which dependencies block your next Django upgrade, then names the smallest safe release for each in order: what to bump today, what has to ship with the Django bump, and what to check by hand. Run it with uvx django-upgrade-report, and use --fail-on to gate CI.
Reach 4,300+ Django developers every Friday. See sponsorship details and rates.