February 3, 2026
Django 6.0.2 fixes three security issues with severity « high », two security issues with severity « moderate », one security issue with severity « low », and several bugs in 6.0.1.
The django.contrib.auth.handlers.modwsgi.check_password() function for
authentication via mod_wsgi
allowed remote attackers to enumerate users via a timing attack.
This issue has severity « low » according to the Django security policy.
When receiving duplicates of a single header, ASGIRequest allowed a remote
attacker to cause a potential denial-of-service via a specifically created
request with multiple duplicate headers. The vulnerability resulted from
repeated string concatenation while combining repeated headers, which
produced super-linear computation resulting in service degradation or outage.
This issue has severity « moderate » according to the Django security policy.
Raster lookups on GIS fields (only implemented on PostGIS) were subject to SQL injection if untrusted data was used as a band index.
Pour rappel, toutes les données non fiables provenant des utilisateurs doivent être validées avant d’être réutilisées.
This issue has severity « high » according to the Django security policy.
django.utils.text.Truncator HTML methods¶django.utils.text.Truncator.chars() and Truncator.words() methods (with
html=True) and the truncatechars_html and
truncatewords_html template filters were subject to a potential
denial-of-service attack via certain inputs with a large number of unmatched
HTML end tags, which could cause quadratic time complexity during HTML parsing.
This issue has severity « moderate » according to the Django security policy.
FilteredRelation was subject to SQL injection in column aliases via
control characters, using a suitably crafted dictionary, with dictionary
expansion, as the **kwargs passed to QuerySet.annotate(),
aggregate(), extra(),
values(), values_list(), and
alias().
This issue has severity « high » according to the Django security policy.
QuerySet.order_by and FilteredRelation¶QuerySet.order_by() was subject to SQL injection in column aliases
containing periods when the same alias was, using a suitably crafted
dictionary, with dictionary expansion, used in FilteredRelation.
This issue has severity « high » according to the Django security policy.
Fixed a visual regression in Django 6.0 that caused the admin filter sidebar to wrap below the changelist when filter elements contained long text (#36850).
Fixed a visual regression in Django 6.0 for admin form fields grouped under a
<fieldset> aligned horizontally (#36788).
Fixed a regression in Django 6.0 where auto_now_add field values were not
populated during INSERT operations, due to incorrect parameters passed to
field.pre_save() (#36847).
août 05, 2026