Django 6.1.2, 6.0.9, and 5.2.18 Fix Four Security Issues
Quick Answer
Django published security releases 6.1.2, 6.0.9, and 5.2.18 for four issues. Match each application to its active supported branch, update, test translation, header parsing, GIS spatial lookups, and model formsets, and preserve evidence.
Update Supported Django Branches And Test Affected Features
What to do now: Inventory supported Django applications, map the active 6.1, 6.0, or 5.2 branch, install the matching fixed release, validate affected features and compatibility, and retain evidence.
Last verified: 2026-10-06 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | Django 6.1, 6.0, and 5.2 release branches |
|---|---|
| Advisory | Django security releases 2026-10-06 |
| CVEs | CVE-2026-77050, CVE-2026-84429, CVE-2026-87890, CVE-2026-87975 |
| Authoritative release date | 2026-10-06 08:00:00 UTC |
| Authority revision date | 2026-10-06 08:00:00 UTC |
| Affected versions | Supported Django 6.1, 6.0, and 5.2 releases before 6.1.2, 6.0.9, and 5.2.18 respectively, subject to the feature-specific conditions in the advisory. |
| Fixed version | Django 6.1.2, 6.0.9, or 5.2.18 for the matching release branch |
| CVSS base score | Not provided by the authority |
| CVSS severity | Low to Moderate |
| Exploitation status | Not stated by the authority; no exploitation claim is inferred. |
What Changed
Django released 6.1.2, 6.0.9, and 5.2.18 for two denial-of-service issues, a spatial-lookup request-forgery issue that corrects an insufficient prior mitigation, and model-formset privilege abuse.
What To Validate Now
- Inventory. Locate Django applications and services; record the framework version, Python environment, GIS use, model formsets, exposed request paths, owner, deployment method, and dependencies.
- Establish applicability. Compare each application with the feature-specific conditions in the Django advisory. Default BigAutoField primary keys are not affected by the model-formset issue; do not infer applicability from framework presence alone.
- Remediate. Upgrade the active supported branch to Django 6.1.2, 6.0.9, or 5.2.18. Review the documented parsing and GDALRaster compatibility changes before deployment.
- Validate. Confirm the installed Django release; test translation, repeated and malformed headers, GIS spatial lookups, affected formsets, authentication, authorization, application health, and rollback.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
The spatial-lookup correction is backward incompatible for raster bytes, and header parsing of malformed or unusual values can differ. Test integrations and custom formsets before broad deployment.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

