Django 2.2 LTS

Current status

end of lifeLTShigh

Django 2.2 reached end of life on 11 Apr 2022. Security and bug fixes are no longer provided by the project according to published lifecycle data.

Official lifecycle source: Django Download / Support Schedule

Support phase
end of life
End of life
11 Apr 2022
Latest release
Released

At a glance

Version line
2.2
Initial release
Lifecycle phase
end of life
Latest stable
Latest release date
EOL
11 Apr 2022
Risk
high
Releases tracked
0

Lifecycle timeline

Phases from published LifecyclePeriod records. Missing phases are not inferred.

  1. extended support

    2 Dec 2019 → 11 Apr 2022

    Source: Django Download / Support Schedule

  2. end of lifecurrent

    11 Apr 2022 → —

    Source: Django Download / Support Schedule

  3. standard support

    — → 2 Dec 2019

    Source: Django Download / Support Schedule

Django 2.2 reached end of life on 11 Apr 2022. Security and bug fixes are no longer provided by the project according to published lifecycle data.

Security

Advisories affecting Django 2.2 (OSV.dev evidence). Known exploited status from CISA KEV when matched.

Known vulnerabilities
15
Known exploited
0
Highest CVSS
9.8
  • CVE-2022-28347GHSA-w24h-v9qh-8gxj

    SQL Injection in Django

    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    >=2.2,<2.2.28
    Fixed in:
    2.2.28
    Source:
    OSV source · Advisory
  • CVE-2022-28346GHSA-2gwj-7jmv-h26r

    SQL Injection in Django

    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    >=2.2,<2.2.28
    Fixed in:
    2.2.28
    Source:
    OSV source · Advisory
  • CVE-2022-28347PYSEC-2022-191
    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    >=2.2,<2.2.28
    Fixed in:
    2.2.28
    Source:
    OSV source · Advisory
  • CVE-2022-28346PYSEC-2022-190
    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    >=2.2,<2.2.28
    Fixed in:
    2.2.28
    Source:
    OSV source · Advisory
  • CVE-2020-7471GHSA-hmr4-m2h5-33qx

    SQL injection in Django

    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    >=2.0,<2.2.10
    Fixed in:
    2.2.10
    Source:
    OSV source · Advisory
  • CVE-2019-14234GHSA-6r97-cj55-9hrq

    SQL Injection in Django

    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    >=2.2a1,<2.2.4
    Fixed in:
    2.2.4
    Source:
    OSV source · Advisory
  • CVE-2019-14234PYSEC-2019-13
    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    >=2.2,<2.2.4
    Fixed in:
    2.2.4
    Source:
    OSV source · Advisory
  • CVE-2025-64459GHSA-frmv-pr5f-9mcr

    Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.

    CVSS:
    9.1 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    <4.2.26
    Fixed in:
    4.2.26
    Source:
    OSV source · Advisory
  • CVE-2022-36359GHSA-8x94-hmjh-97hq

    Django vulnerable to Reflected File Download attack

    CVSS:
    8.8 (high) · NVD
    CWE:
    CWE-494
    Affected:
    <3.2.15
    Fixed in:
    3.2.15
    Source:
    OSV source · Advisory
  • CVE-2020-9402GHSA-3gh2-xw74-jmcw

    SQL injection in Django

    CVSS:
    8.8 (high) · NVD
    CWE:
    CWE-89
    Affected:
    >=2.2,<2.2.11
    Fixed in:
    2.2.11
    Source:
    OSV source · Advisory
  • CVE-2025-57833GHSA-6w2r-r2m5-xq5w

    Django is subject to SQL injection through its column aliases

    CVSS:
    8.1 (high) · NVD
    CWE:
    CWE-89
    Affected:
    <4.2.24
    Fixed in:
    4.2.24
    Source:
    OSV source · Advisory
  • CVE-2025-64458GHSA-qw25-v68c-qjf3

    Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-407
    Affected:
    <4.2.26
    Fixed in:
    4.2.26
    Source:
    OSV source · Advisory
  • CVE-2026-53878GHSA-8qcx-xf44-272x

    Django: DomainNameValidator permits newline characters that may enable HTTP header injection

    CVSS:
    6.1 (moderate) · NVD
    CWE:
    CWE-144
    Affected:
    <5.2.16
    Fixed in:
    5.2.16
    Source:
    OSV source · Advisory
  • CVE-2019-11358PYSEC-2026-628

    XSS in jQuery as used in Drupal, Backdrop CMS, and other products

    CVSS:
    6.1 (moderate) · NVD
    CWE:
    CWE-1321
    Affected:
    >=2.2a1,<2.2.2
    Fixed in:
    2.2.2
    Source:
    OSV source · Advisory
  • CVE-2019-11358GHSA-6c3j-c64m-qhgq

    XSS in jQuery as used in Drupal, Backdrop CMS, and other products

    CVSS:
    6.1 (moderate) · NVD
    CWE:
    CWE-1321
    Affected:
    >=2.2a1,<2.2.2
    Fixed in:
    2.2.2
    Source:
    OSV source · Advisory

Latest release

No releases recorded for this line.

Should I use this version?

Not recommended for new deployments

Upgrade to a currently supported release line. Recommended target: Django 6.1.

Upgrade from 2.2

Recommended target: Django 6.1

Version comparison

Compact comparison against the nearest relevant release lines.

2.26.1
Statusend of lifestandard support
Latest release6.1
EOLApr 2022Dec 2027
Riskhighlow

Sources

Where this information comes from.

Lifecycle sources

Release sources

Data coverage

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Releases tracked
0
Lifecycle periods
3
EOL
Known
Provenance records
4
Data last checked
30 Aug 2026
Latest source update
30 Aug 2026

Other Django versions