Django 1.9

Current status

end of lifehigh

Django 1.9 reached end of life on 4 Apr 2017. Security and bug fixes are no longer provided by the project according to published lifecycle data.

Official lifecycle source: Django Download / Support Schedule

Support phase
end of life
End of life
4 Apr 2017
Latest release
Released

At a glance

Version line
1.9
Initial release
Lifecycle phase
end of life
Latest stable
Latest release date
EOL
4 Apr 2017
Risk
high
Releases tracked
0

Lifecycle timeline

Phases from published LifecyclePeriod records. Missing phases are not inferred.

  1. extended support

    1 Aug 2016 → 4 Apr 2017

    Source: Django Download / Support Schedule

  2. end of lifecurrent

    4 Apr 2017 → —

    Source: Django Download / Support Schedule

  3. standard support

    — → 1 Aug 2016

    Source: Django Download / Support Schedule

Django 1.9 reached end of life on 4 Apr 2017. Security and bug fixes are no longer provided by the project according to published lifecycle data.

Security

Advisories affecting Django 1.9 (OSV.dev evidence). Known exploited status from CISA KEV when matched.

Known vulnerabilities
15
Known exploited
0
Highest CVSS
9.8
  • CVE-2016-9013GHSA-mv8g-fhh6-6267

    Django user with hardcoded password created when running tests on Oracle

    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-798
    Affected:
    >=1.10a1,<1.10.3; >=1.9a1,<1.9.11
    Fixed in:
    1.10.3, 1.9.11
    Source:
    OSV source · Advisory
  • CVE-2020-7471GHSA-hmr4-m2h5-33qx

    SQL injection in Django

    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    <1.11.28
    Fixed in:
    1.11.28
    Source:
    OSV source · Advisory
  • CVE-2025-64459GHSA-frmv-pr5f-9mcr

    Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.

    CVSS:
    9.1 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    <4.2.26
    Fixed in:
    4.2.26
    Source:
    OSV source · Advisory
  • CVE-2022-36359GHSA-8x94-hmjh-97hq

    Django vulnerable to Reflected File Download attack

    CVSS:
    8.8 (high) · NVD
    CWE:
    CWE-494
    Affected:
    <3.2.15
    Fixed in:
    3.2.15
    Source:
    OSV source · Advisory
  • CVE-2025-57833GHSA-6w2r-r2m5-xq5w

    Django is subject to SQL injection through its column aliases

    CVSS:
    8.1 (high) · NVD
    CWE:
    CWE-89
    Affected:
    <4.2.24
    Fixed in:
    4.2.24
    Source:
    OSV source · Advisory
  • CVE-2016-9014GHSA-3f2c-jm6v-cr35

    Django DNS Rebinding Vulnerability

    CVSS:
    8.1 (high) · NVD
    CWE:
    CWE-264
    Affected:
    >=1.10a1,<1.10.3; >=1.9a1,<1.9.11
    Fixed in:
    1.10.3, 1.9.11
    Source:
    OSV source · Advisory
  • CVE-2025-64458GHSA-qw25-v68c-qjf3

    Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-407
    Affected:
    <4.2.26
    Fixed in:
    4.2.26
    Source:
    OSV source · Advisory
  • CVE-2016-7401GHSA-crhm-qpjc-cm64

    Django CSRF Protection Bypass

    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-254
    Affected:
    >=1.9,<1.9.10
    Fixed in:
    1.9.10
    Source:
    OSV source · Advisory
  • CVE-2016-7401PYSEC-2016-3
    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-254
    Affected:
    >=1.9,<1.9.10
    Fixed in:
    1.9.10
    Source:
    OSV source · Advisory
  • CVE-2016-2512GHSA-pw27-w7w4-9qc7

    Django XSS Vulnerability

    CVSS:
    7.4 (high) · NVD
    CWE:
    CWE-79
    Affected:
    >=1.9a1,<1.9.3
    Fixed in:
    1.9.3
    Source:
    OSV source · Advisory
  • CVE-2016-2512PYSEC-2016-15
    CVSS:
    7.4 (high) · NVD
    CWE:
    CWE-79
    Affected:
    >=1.9,<1.9.3
    Fixed in:
    1.9.3
    Source:
    OSV source · Advisory
  • CVE-2026-53878GHSA-8qcx-xf44-272x

    Django: DomainNameValidator permits newline characters that may enable HTTP header injection

    CVSS:
    6.1 (moderate) · NVD
    CWE:
    CWE-144
    Affected:
    <5.2.16
    Fixed in:
    5.2.16
    Source:
    OSV source · Advisory
  • CVE-2016-6186GHSA-c8c8-9472-w52h

    Django Cross-site scripting Vulnerability

    CVSS:
    6.1 (moderate) · NVD
    CWE:
    CWE-79
    Affected:
    >=1.10a1,<1.10rc1; >=1.9,<1.9.8
    Fixed in:
    1.10rc1, 1.9.8
    Source:
    OSV source · Advisory
  • CVE-2016-6186PYSEC-2016-2
    CVSS:
    6.1 (moderate) · NVD
    CWE:
    CWE-79
    Affected:
    >=1.10a0,<1.10rc1
    Fixed in:
    1.10rc1
    Source:
    OSV source · Advisory
  • CVE-2016-2048GHSA-46x4-9jmv-jc8p

    Django Access Restrictions Bypass

    CVSS:
    5.5 (moderate) · NVD
    CWE:
    CWE-284
    Affected:
    >=1.9,<1.9.2
    Fixed in:
    1.9.2
    Source:
    OSV source · Advisory

Latest release

No releases recorded for this line.

Should I use this version?

Not recommended for new deployments

Upgrade to a currently supported release line. Recommended target: Django 6.1.

Upgrade from 1.9

Recommended target: Django 6.1

Version comparison

Compact comparison against the nearest relevant release lines.

1.96.1
Statusend of lifestandard support
Latest release6.1
EOLApr 2017Dec 2027
Riskhighlow

Sources

Where this information comes from.

Lifecycle sources

Release sources

Data coverage

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Releases tracked
0
Lifecycle periods
3
EOL
Known
Provenance records
4
Data last checked
30 Aug 2026
Latest source update
30 Aug 2026

Other Django versions