Django 1.0 lifecycle

Current status

standard supportlow

Django 1.0 is currently in standard support.

Official lifecycle source: PyPI JSON API

Support phase
standard support
End of life
Not officially published
Latest release
1.0.4
Released

At a glance

Version line
1.0
Initial release
Lifecycle phase
standard support
Latest stable
1.0.4
Latest release date
EOL
Not officially published
Risk
low
Releases tracked
4

Lifecycle timeline

Phases from published LifecyclePeriod records. Missing phases are not inferred.

  1. standard supportcurrent

    Dates not published

    Source: PyPI JSON API

Some lifecycle dates are not published by the available sources.

Django 1.0 is currently in standard support.

Security

Advisories affecting Django 1.0 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
15
Known exploited
0
Highest CVSS
10.0
  • CVE-2014-0474GHSA-wqjj-hx84-v449

    Django Vulnerable to MySQL Injection

    CVSS:
    10.0 · NVD
    CWE:
    CWE-399
    Affected:
    <1.4.11
    Fixed in:
    1.4.11
    Source:
    OSV source · Advisory
  • CVE-2020-7471GHSA-hmr4-m2h5-33qx

    SQL injection in Django

    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    <1.11.28
    Fixed in:
    1.11.28
    Source:
    OSV source · Advisory
  • CVE-2025-64459GHSA-frmv-pr5f-9mcr

    Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.

    CVSS:
    9.1 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    <4.2.26
    Fixed in:
    4.2.26
    Source:
    OSV source · Advisory
  • CVE-2022-36359GHSA-8x94-hmjh-97hq

    Django vulnerable to Reflected File Download attack

    CVSS:
    8.8 (high) · NVD
    CWE:
    CWE-494
    Affected:
    <3.2.15
    Fixed in:
    3.2.15
    Source:
    OSV source · Advisory
  • CVE-2025-57833GHSA-6w2r-r2m5-xq5w

    Django is subject to SQL injection through its column aliases

    CVSS:
    8.1 (high) · NVD
    CWE:
    CWE-89
    Affected:
    <4.2.24
    Fixed in:
    4.2.24
    Source:
    OSV source · Advisory
  • CVE-2025-64458GHSA-qw25-v68c-qjf3

    Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-407
    Affected:
    <4.2.26
    Fixed in:
    4.2.26
    Source:
    OSV source · Advisory
  • CVE-2016-7401GHSA-crhm-qpjc-cm64

    Django CSRF Protection Bypass

    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-254
    Affected:
    <1.8.15
    Fixed in:
    1.8.15
    Source:
    OSV source · Advisory
  • CVE-2016-2512GHSA-pw27-w7w4-9qc7

    Django XSS Vulnerability

    CVSS:
    7.4 (high) · NVD
    CWE:
    CWE-79
    Affected:
    <1.8.10
    Fixed in:
    1.8.10
    Source:
    OSV source · Advisory
  • CVE-2026-53878GHSA-8qcx-xf44-272x

    Django: DomainNameValidator permits newline characters that may enable HTTP header injection

    CVSS:
    6.1 (moderate) · NVD
    CWE:
    CWE-144
    Affected:
    <5.2.16
    Fixed in:
    5.2.16
    Source:
    OSV source · Advisory
  • CVE-2016-6186GHSA-c8c8-9472-w52h

    Django Cross-site scripting Vulnerability

    CVSS:
    6.1 (moderate) · NVD
    CWE:
    CWE-79
    Affected:
    <1.8.14
    Fixed in:
    1.8.14
    Source:
    OSV source · Advisory
  • CVE-2014-0482GHSA-625g-gx8c-xcmg

    Django Middleware Enables Session Hijacking

    CVSS:
    6.0 · NVD
    CWE:
    CWE-287
    Affected:
    <1.4.14
    Fixed in:
    1.4.14
    Source:
    OSV source · Advisory
  • CVE-2014-0480GHSA-f7cm-ccfp-3q4r

    Django Incorrectly Validates URLs

    CVSS:
    5.8 · NVD
    CWE:
    CWE-20
    Affected:
    <1.4.14
    Fixed in:
    1.4.14
    Source:
    OSV source · Advisory
  • CVE-2008-3909PYSEC-2008-2
    CVSS:
    5.8 · NVD
    CWE:
    CWE-352
    Affected:
    <1.1
    Fixed in:
    1.1
    Source:
    OSV source · Advisory
  • CVE-2026-48588GHSA-3h9f-r86x-qvjx

    Django: cache middleware may expose private responses when unrelated request cookies are present

    CVSS:
    5.3 (moderate) · NVD
    CWE:
    CWE-524
    Affected:
    <5.2.16
    Fixed in:
    5.2.16
    Source:
    OSV source · Advisory
  • CVE-2026-48587GHSA-923m-gv2p-w5qp

    Django: has_vary_header may expose cached responses when Vary values contain whitespace

    CVSS:
    5.3 (moderate) · NVD
    CWE:
    CWE-1023
    Affected:
    <5.2.15
    Fixed in:
    5.2.15
    Source:
    OSV source · Advisory

Latest release

1.0.4

Released · stable

https://pypi.org/project/Django/1.0.4/

Previous releases

  • 1.0.3

  • 1.0.2

  • 1.0.1

Release history

4 concrete releases tracked for this line.

VersionRelease dateChannelSource
1.0.4stableSource
1.0.3stableSource
1.0.2stableSource
1.0.1stableSource

Release activity

Total releases
4
Last 30 days
0
Last 90 days
0

Should I use this version?

Suitable for new deployments

Django 1.0 is currently supported (standard support).

Upgrade options

Newer supported Django version lines from CompatHub lifecycle data. Compatibility and security context use existing evidence only.

You are on Django 1.0

Supported

Supported upgrade options

Open full upgrade planner for Django 1.0

Version comparison

Compact comparison against the nearest relevant release lines.

1.06.1
Statusstandard supportstandard support
Latest release1.0.46.1
EOLNot publishedDec 2027
Risklowlow

Sources

Where this information comes from.

Lifecycle sources

Release sources

Data coverage

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Releases tracked
4
Lifecycle periods
1
EOL
Not officially published
Provenance records
2
Data last checked
1 Sept 2026
Latest source update
1 Sept 2026

EOL: Not officially published

Other Django versions