Django 6.0.2 release notes#
February 3, 2026
Django 6.0.2 fixes three security issues with severity “high”, two security issues with severity “moderate”, one security issue with severity “low”, and several bugs in 6.0.1.
CVE-2025-13473: Username enumeration through timing difference in mod_wsgi authentication handler#
The django.contrib.auth.handlers.modwsgi.check_password() function for
authentication via mod_wsgi
allowed remote attackers to enumerate users via a timing attack.
This issue has severity “low” according to the Django security policy.
CVE-2025-14550: Potential denial-of-service vulnerability via repeated headers when using ASGI#
When receiving duplicates of a single header, ASGIRequest allowed a remote
attacker to cause a potential denial-of-service via a specifically created
request with multiple duplicate headers. The vulnerability resulted from
repeated string concatenation while combining repeated headers, which
produced super-linear computation resulting in service degradation or outage.
This issue has severity “moderate” according to the Django security policy.
CVE-2026-1207: Potential SQL injection via raster lookups on PostGIS#
Raster lookups on GIS fields (only implemented on PostGIS) were subject to SQL injection if untrusted data was used as a band index.
As a reminder, all untrusted user input should be validated before use.
This issue has severity “high” according to the Django security policy.
CVE-2026-1285: Potential denial-of-service vulnerability in django.utils.text.Truncator HTML methods#
django.utils.text.Truncator.chars() and Truncator.words() methods (with
html=True) and the truncatechars_html and
truncatewords_html template filters were subject to a potential
denial-of-service attack via certain inputs with a large number of unmatched
HTML end tags, which could cause quadratic time complexity during HTML parsing.
This issue has severity “moderate” according to the Django security policy.
CVE-2026-1287: Potential SQL injection in column aliases via control characters#
FilteredRelation was subject to SQL injection in column aliases via
control characters, using a suitably crafted dictionary, with dictionary
expansion, as the **kwargs passed to QuerySet.annotate(),
aggregate(), extra(),
values(), values_list(), and
alias().
This issue has severity “high” according to the Django security policy.
CVE-2026-1312: Potential SQL injection via QuerySet.order_by and FilteredRelation#
QuerySet.order_by() was subject to SQL injection in column aliases
containing periods when the same alias was, using a suitably crafted
dictionary, with dictionary expansion, used in FilteredRelation.
This issue has severity “high” according to the Django security policy.
Bugfixes#
Fixed a visual regression in Django 6.0 that caused the admin filter sidebar to wrap below the changelist when filter elements contained long text (#36850).
Fixed a visual regression in Django 6.0 for admin form fields grouped under a
<fieldset>aligned horizontally (#36788).Fixed a regression in Django 6.0 where
auto_now_addfield values were not populated duringINSERToperations, due to incorrect parameters passed tofield.pre_save()(#36847).