Django 1.6
Current status
Django 1.6 reached end of life on 1 Apr 2015. Security and bug fixes are no longer provided by the project according to published lifecycle data.
Official lifecycle source: Django Download / Support Schedule
- Support phase
- end of life
- End of life
- 1 Apr 2015
- Latest release
- —
- Released
- —
At a glance
- Version line
- 1.6
- Initial release
- —
- Lifecycle phase
- end of life
- Latest stable
- —
- Latest release date
- —
- EOL
- 1 Apr 2015
- Risk
- high
- Releases tracked
- 0
Lifecycle timeline
Phases from published LifecyclePeriod records. Missing phases are not inferred.
extended support
2 Sept 2014 → 1 Apr 2015
Source: Django Download / Support Schedule
end of lifecurrent
1 Apr 2015 → —
Source: Django Download / Support Schedule
standard support
— → 2 Sept 2014
Source: Django Download / Support Schedule
Django 1.6 reached end of life on 1 Apr 2015. Security and bug fixes are no longer provided by the project according to published lifecycle data.
Security
Advisories affecting Django 1.6 (OSV.dev evidence). Known exploited status from CISA KEV when matched.
- Known vulnerabilities
- 15
- Known exploited
- 0
- Highest CVSS
- 10.0
- CVE-2014-0474GHSA-wqjj-hx84-v449
Django Vulnerable to MySQL Injection
- CVSS:
- 10.0 · NVD
- CWE:
- CWE-399
- Affected:
- >=1.6,<1.6.3
- Fixed in:
- 1.6.3
- Source:
- OSV source · Advisory
- CVE-2014-0474PYSEC-2014-3
- CVSS:
- 10.0 · NVD
- CWE:
- CWE-399
- Affected:
- >=1.6,<1.6.3
- Fixed in:
- 1.6.3
- Source:
- OSV source · Advisory
- CVE-2020-7471GHSA-hmr4-m2h5-33qx
SQL injection in Django
- CVSS:
- 9.8 (critical) · NVD
- CWE:
- CWE-89
- Affected:
- <1.11.28
- Fixed in:
- 1.11.28
- Source:
- OSV source · Advisory
- CVE-2025-64459GHSA-frmv-pr5f-9mcr
Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
- CVSS:
- 9.1 (critical) · NVD
- CWE:
- CWE-89
- Affected:
- <4.2.26
- Fixed in:
- 4.2.26
- Source:
- OSV source · Advisory
- CVE-2022-36359GHSA-8x94-hmjh-97hq
Django vulnerable to Reflected File Download attack
- CVSS:
- 8.8 (high) · NVD
- CWE:
- CWE-494
- Affected:
- <3.2.15
- Fixed in:
- 3.2.15
- Source:
- OSV source · Advisory
- CVE-2025-57833GHSA-6w2r-r2m5-xq5w
Django is subject to SQL injection through its column aliases
- CVSS:
- 8.1 (high) · NVD
- CWE:
- CWE-89
- Affected:
- <4.2.24
- Fixed in:
- 4.2.24
- Source:
- OSV source · Advisory
- CVE-2025-64458GHSA-qw25-v68c-qjf3
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-407
- Affected:
- <4.2.26
- Fixed in:
- 4.2.26
- Source:
- OSV source · Advisory
- CVE-2016-7401GHSA-crhm-qpjc-cm64
Django CSRF Protection Bypass
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-254
- Affected:
- <1.8.15
- Fixed in:
- 1.8.15
- Source:
- OSV source · Advisory
- CVE-2016-2512GHSA-pw27-w7w4-9qc7
Django XSS Vulnerability
- CVSS:
- 7.4 (high) · NVD
- CWE:
- CWE-79
- Affected:
- <1.8.10
- Fixed in:
- 1.8.10
- Source:
- OSV source · Advisory
- CVE-2014-1418GHSA-q7q2-qf2q-rw3w
Django Vulnerable to Cache Poisoning
- CVSS:
- 6.4 · NVD
- Affected:
- >=1.7a1,<1.7b4; >=1.6,<1.6.5
- Fixed in:
- 1.7b4, 1.6.5
- Source:
- OSV source · Advisory
- CVE-2014-1418PYSEC-2014-19
- CVSS:
- 6.4 · NVD
- Affected:
- >=1.7a0,<1.7b4
- Fixed in:
- 1.7b4
- Source:
- OSV source · Advisory
- CVE-2026-53878GHSA-8qcx-xf44-272x
Django: DomainNameValidator permits newline characters that may enable HTTP header injection
- CVSS:
- 6.1 (moderate) · NVD
- CWE:
- CWE-144
- Affected:
- <5.2.16
- Fixed in:
- 5.2.16
- Source:
- OSV source · Advisory
- CVE-2016-6186GHSA-c8c8-9472-w52h
Django Cross-site scripting Vulnerability
- CVSS:
- 6.1 (moderate) · NVD
- CWE:
- CWE-79
- Affected:
- <1.8.14
- Fixed in:
- 1.8.14
- Source:
- OSV source · Advisory
- CVE-2014-0482GHSA-625g-gx8c-xcmg
Django Middleware Enables Session Hijacking
- CVSS:
- 6.0 · NVD
- CWE:
- CWE-287
- Affected:
- >=1.6,<1.6.6; >=1.7a1,<1.7c3
- Fixed in:
- 1.6.6, 1.7c3
- Source:
- OSV source · Advisory
- CVE-2014-0482PYSEC-2014-6
- CVSS:
- 6.0 · NVD
- CWE:
- CWE-287
- Affected:
- >=1.6,<1.6.6
- Fixed in:
- 1.6.6
- Source:
- OSV source · Advisory
Latest release
No releases recorded for this line.
Should I use this version?
Not recommended for new deployments
Upgrade to a currently supported release line. Recommended target: Django 6.1.
Upgrade from 1.6
Recommended target: Django 6.1
Version comparison
Compact comparison against the nearest relevant release lines.
Sources
Where this information comes from.
Lifecycle sources
- Django Download / Support Schedulefirst party · high confidence
Official source: https://www.djangoproject.com/download/
Last verified 30 Aug 2026
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Verification time not recorded
- OSV.devfirst party
Official source: https://osv.dev
Verification time not recorded
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Verification time not recorded
- PyPI JSON APIfirst party
Official source: https://pypi.org
Verification time not recorded
Release sources
- Django Download / Support Schedulefirst party · high confidence
Official source: https://www.djangoproject.com/download/
Last verified 30 Aug 2026
Data coverage
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Releases tracked
- 0
- Lifecycle periods
- 3
- EOL
- Known
- Provenance records
- 4
- Data last checked
- 30 Aug 2026
- Latest source update
- 30 Aug 2026
