Django 6.1.2, 6.0.9, and 5.2.18 Fix Four Security Issues

P2 — VALIDATE AND UPDATELow to Moderate · Not provided by the authorityEXPLOITATION: NOT STATED

Quick Answer

Django published security releases 6.1.2, 6.0.9, and 5.2.18 for four issues. Match each application to its active supported branch, update, test translation, header parsing, GIS spatial lookups, and model formsets, and preserve evidence.

Update Supported Django Branches And Test Affected Features

What to do now: Inventory supported Django applications, map the active 6.1, 6.0, or 5.2 branch, install the matching fixed release, validate affected features and compatibility, and retain evidence.

Open the authoritative advisory

Last verified: 2026-10-06 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeDjango 6.1, 6.0, and 5.2 release branches
AdvisoryDjango security releases 2026-10-06
CVEsCVE-2026-77050, CVE-2026-84429, CVE-2026-87890, CVE-2026-87975
Authoritative release date2026-10-06 08:00:00 UTC
Authority revision date2026-10-06 08:00:00 UTC
Affected versionsSupported Django 6.1, 6.0, and 5.2 releases before 6.1.2, 6.0.9, and 5.2.18 respectively, subject to the feature-specific conditions in the advisory.
Fixed versionDjango 6.1.2, 6.0.9, or 5.2.18 for the matching release branch
CVSS base scoreNot provided by the authority
CVSS severityLow to Moderate
Exploitation statusNot stated by the authority; no exploitation claim is inferred.

What Changed

Django released 6.1.2, 6.0.9, and 5.2.18 for two denial-of-service issues, a spatial-lookup request-forgery issue that corrects an insufficient prior mitigation, and model-formset privilege abuse.

What To Validate Now

  1. Inventory. Locate Django applications and services; record the framework version, Python environment, GIS use, model formsets, exposed request paths, owner, deployment method, and dependencies.
  2. Establish applicability. Compare each application with the feature-specific conditions in the Django advisory. Default BigAutoField primary keys are not affected by the model-formset issue; do not infer applicability from framework presence alone.
  3. Remediate. Upgrade the active supported branch to Django 6.1.2, 6.0.9, or 5.2.18. Review the documented parsing and GDALRaster compatibility changes before deployment.
  4. Validate. Confirm the installed Django release; test translation, repeated and malformed headers, GIS spatial lookups, affected formsets, authentication, authorization, application health, and rollback.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

The spatial-lookup correction is backward incompatible for raster bytes, and header parsing of malformed or unusual values can differ. Test integrations and custom formsets before broad deployment.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.