Django 1.0 lifecycle
Current status
Django 1.0 is currently in standard support.
Official lifecycle source: PyPI JSON API
- Support phase
- standard support
- End of life
- Not officially published
- Latest release
- 1.0.4
- Released
- —
At a glance
- Version line
- 1.0
- Initial release
- —
- Lifecycle phase
- standard support
- Latest stable
- 1.0.4
- Latest release date
- —
- EOL
- Not officially published
- Risk
- low
- Releases tracked
- 4
Lifecycle timeline
Phases from published LifecyclePeriod records. Missing phases are not inferred.
standard supportcurrent
Dates not published
Source: PyPI JSON API
Some lifecycle dates are not published by the available sources.
Django 1.0 is currently in standard support.
Security
Advisories affecting Django 1.0 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 15
- Known exploited
- 0
- Highest CVSS
- 10.0
- CVE-2014-0474GHSA-wqjj-hx84-v449
Django Vulnerable to MySQL Injection
- CVSS:
- 10.0 · NVD
- CWE:
- CWE-399
- Affected:
- <1.4.11
- Fixed in:
- 1.4.11
- Source:
- OSV source · Advisory
- CVE-2020-7471GHSA-hmr4-m2h5-33qx
SQL injection in Django
- CVSS:
- 9.8 (critical) · NVD
- CWE:
- CWE-89
- Affected:
- <1.11.28
- Fixed in:
- 1.11.28
- Source:
- OSV source · Advisory
- CVE-2025-64459GHSA-frmv-pr5f-9mcr
Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
- CVSS:
- 9.1 (critical) · NVD
- CWE:
- CWE-89
- Affected:
- <4.2.26
- Fixed in:
- 4.2.26
- Source:
- OSV source · Advisory
- CVE-2022-36359GHSA-8x94-hmjh-97hq
Django vulnerable to Reflected File Download attack
- CVSS:
- 8.8 (high) · NVD
- CWE:
- CWE-494
- Affected:
- <3.2.15
- Fixed in:
- 3.2.15
- Source:
- OSV source · Advisory
- CVE-2025-57833GHSA-6w2r-r2m5-xq5w
Django is subject to SQL injection through its column aliases
- CVSS:
- 8.1 (high) · NVD
- CWE:
- CWE-89
- Affected:
- <4.2.24
- Fixed in:
- 4.2.24
- Source:
- OSV source · Advisory
- CVE-2025-64458GHSA-qw25-v68c-qjf3
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-407
- Affected:
- <4.2.26
- Fixed in:
- 4.2.26
- Source:
- OSV source · Advisory
- CVE-2016-7401GHSA-crhm-qpjc-cm64
Django CSRF Protection Bypass
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-254
- Affected:
- <1.8.15
- Fixed in:
- 1.8.15
- Source:
- OSV source · Advisory
- CVE-2016-2512GHSA-pw27-w7w4-9qc7
Django XSS Vulnerability
- CVSS:
- 7.4 (high) · NVD
- CWE:
- CWE-79
- Affected:
- <1.8.10
- Fixed in:
- 1.8.10
- Source:
- OSV source · Advisory
- CVE-2026-53878GHSA-8qcx-xf44-272x
Django: DomainNameValidator permits newline characters that may enable HTTP header injection
- CVSS:
- 6.1 (moderate) · NVD
- CWE:
- CWE-144
- Affected:
- <5.2.16
- Fixed in:
- 5.2.16
- Source:
- OSV source · Advisory
- CVE-2016-6186GHSA-c8c8-9472-w52h
Django Cross-site scripting Vulnerability
- CVSS:
- 6.1 (moderate) · NVD
- CWE:
- CWE-79
- Affected:
- <1.8.14
- Fixed in:
- 1.8.14
- Source:
- OSV source · Advisory
- CVE-2014-0482GHSA-625g-gx8c-xcmg
Django Middleware Enables Session Hijacking
- CVSS:
- 6.0 · NVD
- CWE:
- CWE-287
- Affected:
- <1.4.14
- Fixed in:
- 1.4.14
- Source:
- OSV source · Advisory
- CVE-2014-0480GHSA-f7cm-ccfp-3q4r
Django Incorrectly Validates URLs
- CVSS:
- 5.8 · NVD
- CWE:
- CWE-20
- Affected:
- <1.4.14
- Fixed in:
- 1.4.14
- Source:
- OSV source · Advisory
- CVE-2008-3909PYSEC-2008-2
- CVSS:
- 5.8 · NVD
- CWE:
- CWE-352
- Affected:
- <1.1
- Fixed in:
- 1.1
- Source:
- OSV source · Advisory
- CVE-2026-48588GHSA-3h9f-r86x-qvjx
Django: cache middleware may expose private responses when unrelated request cookies are present
- CVSS:
- 5.3 (moderate) · NVD
- CWE:
- CWE-524
- Affected:
- <5.2.16
- Fixed in:
- 5.2.16
- Source:
- OSV source · Advisory
- CVE-2026-48587GHSA-923m-gv2p-w5qp
Django: has_vary_header may expose cached responses when Vary values contain whitespace
- CVSS:
- 5.3 (moderate) · NVD
- CWE:
- CWE-1023
- Affected:
- <5.2.15
- Fixed in:
- 5.2.15
- Source:
- OSV source · Advisory
Latest release
Previous releases
1.0.3
—
1.0.2
—
1.0.1
—
Release history
4 concrete releases tracked for this line.
Release activity
- Total releases
- 4
- Last 30 days
- 0
- Last 90 days
- 0
Should I use this version?
Suitable for new deployments
Django 1.0 is currently supported (standard support).
Upgrade options
Newer supported Django version lines from CompatHub lifecycle data. Compatibility and security context use existing evidence only.
You are on Django 1.0
Supported
Supported upgrade options
- Django 5.2Upgrade planner →SupportedEOL 1 April 2028· 4 major versions newer
- Django 6.1Upgrade planner →SupportedEOL 1 December 2027· 5 major versions newer
- Django 6.0Upgrade planner →SupportedEOL 1 April 2027· 5 major versions newer
Version comparison
Compact comparison against the nearest relevant release lines.
Sources
Where this information comes from.
Lifecycle sources
- PyPI JSON APIfirst party · high confidence
Official source: https://pypi.org
Last verified 1 Sept 2026
- OSV.devfirst party
Official source: https://osv.dev
Verification time not recorded
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Verification time not recorded
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Verification time not recorded
Release sources
- PyPI JSON APIfirst party · high confidence
Official source: https://pypi.org
Last verified 1 Sept 2026
- Django Download / Support Schedulefirst party
Official source: https://www.djangoproject.com/download/
Verification time not recorded
Data coverage
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Releases tracked
- 4
- Lifecycle periods
- 1
- EOL
- Not officially published
- Provenance records
- 2
- Data last checked
- 1 Sept 2026
- Latest source update
- 1 Sept 2026
EOL: Not officially published
