Django 2.1
Current status
Django 2.1 reached end of life on 2 Dec 2019. Security and bug fixes are no longer provided by the project according to published lifecycle data.
Official lifecycle source: Django Download / Support Schedule
- Support phase
- end of life
- End of life
- 2 Dec 2019
- Latest release
- —
- Released
- —
At a glance
- Version line
- 2.1
- Initial release
- —
- Lifecycle phase
- end of life
- Latest stable
- —
- Latest release date
- —
- EOL
- 2 Dec 2019
- Risk
- high
- Releases tracked
- 0
Lifecycle timeline
Phases from published LifecyclePeriod records. Missing phases are not inferred.
extended support
1 Apr 2019 → 2 Dec 2019
Source: Django Download / Support Schedule
end of lifecurrent
2 Dec 2019 → —
Source: Django Download / Support Schedule
standard support
— → 1 Apr 2019
Source: Django Download / Support Schedule
Django 2.1 reached end of life on 2 Dec 2019. Security and bug fixes are no longer provided by the project according to published lifecycle data.
Security
Advisories affecting Django 2.1 (OSV.dev evidence). Known exploited status from CISA KEV when matched.
- Known vulnerabilities
- 15
- Known exploited
- 0
- Highest CVSS
- 9.8
- CVE-2020-7471GHSA-hmr4-m2h5-33qx
SQL injection in Django
- CVSS:
- 9.8 (critical) · NVD
- CWE:
- CWE-89
- Affected:
- >=2.0,<2.2.10
- Fixed in:
- 2.2.10
- Source:
- OSV source · Advisory
- CVE-2019-14234GHSA-6r97-cj55-9hrq
SQL Injection in Django
- CVSS:
- 9.8 (critical) · NVD
- CWE:
- CWE-89
- Affected:
- >=2.2a1,<2.2.4; >=2.1a1,<2.1.11
- Fixed in:
- 2.2.4, 2.1.11
- Source:
- OSV source · Advisory
- CVE-2025-64459GHSA-frmv-pr5f-9mcr
Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
- CVSS:
- 9.1 (critical) · NVD
- CWE:
- CWE-89
- Affected:
- <4.2.26
- Fixed in:
- 4.2.26
- Source:
- OSV source · Advisory
- CVE-2022-36359GHSA-8x94-hmjh-97hq
Django vulnerable to Reflected File Download attack
- CVSS:
- 8.8 (high) · NVD
- CWE:
- CWE-494
- Affected:
- <3.2.15
- Fixed in:
- 3.2.15
- Source:
- OSV source · Advisory
- CVE-2025-57833GHSA-6w2r-r2m5-xq5w
Django is subject to SQL injection through its column aliases
- CVSS:
- 8.1 (high) · NVD
- CWE:
- CWE-89
- Affected:
- <4.2.24
- Fixed in:
- 4.2.24
- Source:
- OSV source · Advisory
- CVE-2025-64458GHSA-qw25-v68c-qjf3
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-407
- Affected:
- <4.2.26
- Fixed in:
- 4.2.26
- Source:
- OSV source · Advisory
- CVE-2026-53878GHSA-8qcx-xf44-272x
Django: DomainNameValidator permits newline characters that may enable HTTP header injection
- CVSS:
- 6.1 (moderate) · NVD
- CWE:
- CWE-144
- Affected:
- <5.2.16
- Fixed in:
- 5.2.16
- Source:
- OSV source · Advisory
- CVE-2019-11358PYSEC-2026-628
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
- CVSS:
- 6.1 (moderate) · NVD
- CWE:
- CWE-1321
- Affected:
- >=2.2a1,<2.2.2
- Fixed in:
- 2.2.2
- Source:
- OSV source · Advisory
- CVE-2019-11358GHSA-6c3j-c64m-qhgq
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
- CVSS:
- 6.1 (moderate) · NVD
- CWE:
- CWE-1321
- Affected:
- >=2.0a1,<2.1.9; >=2.2a1,<2.2.2
- Fixed in:
- 2.1.9, 2.2.2
- Source:
- OSV source · Advisory
- CVE-2026-48588GHSA-3h9f-r86x-qvjx
Django: cache middleware may expose private responses when unrelated request cookies are present
- CVSS:
- 5.3 (moderate) · NVD
- CWE:
- CWE-524
- Affected:
- <5.2.16
- Fixed in:
- 5.2.16
- Source:
- OSV source · Advisory
- CVE-2026-48587GHSA-923m-gv2p-w5qp
Django: has_vary_header may expose cached responses when Vary values contain whitespace
- CVSS:
- 5.3 (moderate) · NVD
- CWE:
- CWE-1023
- Affected:
- <5.2.15
- Fixed in:
- 5.2.15
- Source:
- OSV source · Advisory
- CVE-2026-8404GHSA-8cjm-8mp7-r2xf
Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
- CVSS:
- 5.3 (moderate) · NVD
- CWE:
- CWE-178
- Affected:
- <5.2.15
- Fixed in:
- 5.2.15
- Source:
- OSV source · Advisory
- CVE-2025-48432GHSA-7xr5-9hcq-chf9
Django Improper Output Neutralization for Logs vulnerability
- CVSS:
- 5.3 (moderate) · NVD
- CWE:
- CWE-117
- Affected:
- <4.2.22
- Fixed in:
- 4.2.22
- Source:
- OSV source · Advisory
- CVE-2024-45231GHSA-rrqc-c2jx-6jgv
Django allows enumeration of user e-mail addresses
- CVSS:
- 5.3 (moderate) · NVD
- CWE:
- CWE-203
- Affected:
- <4.2.16
- Fixed in:
- 4.2.16
- Source:
- OSV source · Advisory
- CVE-2026-53877GHSA-crhf-3pfg-w68w
Django: GDALRaster may over-read heap memory when constructed from bytes
- CVSS:
- 4.8 (moderate) · NVD
- CWE:
- CWE-805
- Affected:
- <5.2.16
- Fixed in:
- 5.2.16
- Source:
- OSV source · Advisory
Latest release
No releases recorded for this line.
Should I use this version?
Not recommended for new deployments
Upgrade to a currently supported release line. Recommended target: Django 6.1.
Upgrade from 2.1
Recommended target: Django 6.1
Version comparison
Compact comparison against the nearest relevant release lines.
Sources
Where this information comes from.
Lifecycle sources
- Django Download / Support Schedulefirst party · high confidence
Official source: https://www.djangoproject.com/download/
Last verified 30 Aug 2026
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Verification time not recorded
- OSV.devfirst party
Official source: https://osv.dev
Verification time not recorded
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Verification time not recorded
- PyPI JSON APIfirst party
Official source: https://pypi.org
Verification time not recorded
Release sources
- Django Download / Support Schedulefirst party · high confidence
Official source: https://www.djangoproject.com/download/
Last verified 30 Aug 2026
Data coverage
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Releases tracked
- 0
- Lifecycle periods
- 3
- EOL
- Known
- Provenance records
- 4
- Data last checked
- 30 Aug 2026
- Latest source update
- 30 Aug 2026
