Dev News Daily ENDE

Django stops taking new security reports through HackerOne; email only now

The Django Security Team announced on 8 October that the project no longer accepts new security reports through HackerOne. New vulnerabilities in Django should be reported by email to security@djangoproject.com, following the reporting process in Django's security policy.

What happens to existing reports. Reports already submitted on HackerOne remain open and will continue to be handled by the security team; nobody needs to re-file.

Django stops taking new security reports through HackerOne; email only now
Django stops taking new security reports through HackerOne; email only now — Dev News Daily

What the announcement does not say. The post gives no reason for the change and does not say anything about bounties, so it would be a guess to read it as a funding or policy decision. What it does change is practical: a researcher who opens HackerOne looking for Django will find the intake closed and needs to use the email address instead. Django's security policy, linked from the post, remains the reference for what to include and how disclosure is coordinated.

Why it is worth knowing now. Django shipped four CVEs in its 6.1.2, 6.0.9 and 5.2.18 security releases on 6 October, and the framework's security process is one many Python teams depend on without thinking about it. If your organisation runs a scanner or a research programme that reports upstream automatically, check that it does not still target the HackerOne programme. And if you maintain a list of "where to report" for your dependencies, this is an entry to update.

Source: Django Weblog, "Django security reporting update", The Django Security Team, 8 October 2026 — https://www.djangoproject.com/weblog/2026/oct/08/django-security-reporting-update/

Written by Victoria Shinder.