Dev News Daily ENDE

Django 6.1.2, 6.0.9 and 5.2.18 fix four security issues, one with a backward-incompatible change

The Django project issued security releases 6.1.2, 6.0.9 and 5.2.18 on 6 October and asks all users to upgrade as soon as possible. The patches cover the main, 6.1, 6.0 and 5.2 branches.

Django 6.1.2, 6.0.9 and 5.2.18 fix four security issues, one with a backward-incompatible change
Django 6.1.2, 6.0.9 and 5.2.18 fix four security issues, one with a backward-incompatible change — Dev News Daily

The four issues.

  • CVE-2026-84429, moderate. django.utils.http.parse_header_parameters() had quadratic time complexity on values with many separators inside a quoted parameter. An unauthenticated request could reach it through headers such as Accept or Content-Type, for example via HttpRequest.accepts(), and the per-call length limit did not bound repeated headers. The function now uses Python's email.message.Message, so some malformed or unusual header values may parse differently.
  • CVE-2026-77050, low. get_supported_language_variant() cached language codes before limiting their length; many long codes could consume excessive memory. Codes over 500 characters are now rejected or truncated first.
  • CVE-2026-87890, request forgery via spatial lookups. GIS lookups accepted raster values as raw bytes; such bytes could contain a VRT document pointing at an external source and make GDAL issue network requests as the Django process user. Raster bytes must now be wrapped in GDALRaster. The project flags this as a backward-incompatible change; valid hexadecimal geometries are still accepted.
  • CVE-2026-87975, model formsets. Forged POST data could delete instances outside the formset's queryset, or create instances through edit-only formsets, when the primary key could be set through the form (a OneToOneField, or a natural or UUID key among the form's fields).

What to do. Upgrade to the release for your branch. Code that passes raster bytes to spatial lookups needs the GDALRaster wrapper before the upgrade will keep working.

Written by Victoria Shinder.