Django 3.0

Current status

end of lifehigh

Django 3.0 reached end of life on 6 Apr 2021. Security and bug fixes are no longer provided by the project according to published lifecycle data.

Official lifecycle source: Django Download / Support Schedule

Support phase
end of life
End of life
6 Apr 2021
Latest release
Released

At a glance

Version line
3.0
Initial release
Lifecycle phase
end of life
Latest stable
Latest release date
EOL
6 Apr 2021
Risk
high
Releases tracked
0

Lifecycle timeline

Phases from published LifecyclePeriod records. Missing phases are not inferred.

  1. extended support

    3 Aug 2020 → 6 Apr 2021

    Source: Django Download / Support Schedule

  2. end of lifecurrent

    6 Apr 2021 → —

    Source: Django Download / Support Schedule

  3. standard support

    — → 3 Aug 2020

    Source: Django Download / Support Schedule

Django 3.0 reached end of life on 6 Apr 2021. Security and bug fixes are no longer provided by the project according to published lifecycle data.

Security

Advisories affecting Django 3.0 (OSV.dev evidence). Known exploited status from CISA KEV when matched.

Known vulnerabilities
15
Known exploited
0
Highest CVSS
9.8
  • CVE-2020-7471GHSA-hmr4-m2h5-33qx

    SQL injection in Django

    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    >=3.0,<3.0.3
    Fixed in:
    3.0.3
    Source:
    OSV source · Advisory
  • CVE-2020-7471PYSEC-2020-35
    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    >=3.0,<3.0.3
    Fixed in:
    3.0.3
    Source:
    OSV source · Advisory
  • CVE-2025-64459GHSA-frmv-pr5f-9mcr

    Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.

    CVSS:
    9.1 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    <4.2.26
    Fixed in:
    4.2.26
    Source:
    OSV source · Advisory
  • CVE-2022-36359GHSA-8x94-hmjh-97hq

    Django vulnerable to Reflected File Download attack

    CVSS:
    8.8 (high) · NVD
    CWE:
    CWE-494
    Affected:
    <3.2.15
    Fixed in:
    3.2.15
    Source:
    OSV source · Advisory
  • CVE-2020-9402GHSA-3gh2-xw74-jmcw

    SQL injection in Django

    CVSS:
    8.8 (high) · NVD
    CWE:
    CWE-89
    Affected:
    >=3.0,<3.0.4
    Fixed in:
    3.0.4
    Source:
    OSV source · Advisory
  • CVE-2020-9402PYSEC-2020-36
    CVSS:
    8.8 (high) · NVD
    CWE:
    CWE-89
    Affected:
    >=3.0,<3.0.4
    Fixed in:
    3.0.4
    Source:
    OSV source · Advisory
  • CVE-2025-57833GHSA-6w2r-r2m5-xq5w

    Django is subject to SQL injection through its column aliases

    CVSS:
    8.1 (high) · NVD
    CWE:
    CWE-89
    Affected:
    <4.2.24
    Fixed in:
    4.2.24
    Source:
    OSV source · Advisory
  • CVE-2025-64458GHSA-qw25-v68c-qjf3

    Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-407
    Affected:
    <4.2.26
    Fixed in:
    4.2.26
    Source:
    OSV source · Advisory
  • CVE-2026-53878GHSA-8qcx-xf44-272x

    Django: DomainNameValidator permits newline characters that may enable HTTP header injection

    CVSS:
    6.1 (moderate) · NVD
    CWE:
    CWE-144
    Affected:
    <5.2.16
    Fixed in:
    5.2.16
    Source:
    OSV source · Advisory
  • CVE-2026-48588GHSA-3h9f-r86x-qvjx

    Django: cache middleware may expose private responses when unrelated request cookies are present

    CVSS:
    5.3 (moderate) · NVD
    CWE:
    CWE-524
    Affected:
    <5.2.16
    Fixed in:
    5.2.16
    Source:
    OSV source · Advisory
  • CVE-2026-48587GHSA-923m-gv2p-w5qp

    Django: has_vary_header may expose cached responses when Vary values contain whitespace

    CVSS:
    5.3 (moderate) · NVD
    CWE:
    CWE-1023
    Affected:
    <5.2.15
    Fixed in:
    5.2.15
    Source:
    OSV source · Advisory
  • CVE-2026-8404GHSA-8cjm-8mp7-r2xf

    Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling

    CVSS:
    5.3 (moderate) · NVD
    CWE:
    CWE-178
    Affected:
    <5.2.15
    Fixed in:
    5.2.15
    Source:
    OSV source · Advisory
  • CVE-2025-48432GHSA-7xr5-9hcq-chf9

    Django Improper Output Neutralization for Logs vulnerability

    CVSS:
    5.3 (moderate) · NVD
    CWE:
    CWE-117
    Affected:
    <4.2.22
    Fixed in:
    4.2.22
    Source:
    OSV source · Advisory
  • CVE-2024-45231GHSA-rrqc-c2jx-6jgv

    Django allows enumeration of user e-mail addresses

    CVSS:
    5.3 (moderate) · NVD
    CWE:
    CWE-203
    Affected:
    <4.2.16
    Fixed in:
    4.2.16
    Source:
    OSV source · Advisory
  • CVE-2026-53877GHSA-crhf-3pfg-w68w

    Django: GDALRaster may over-read heap memory when constructed from bytes

    CVSS:
    4.8 (moderate) · NVD
    CWE:
    CWE-805
    Affected:
    <5.2.16
    Fixed in:
    5.2.16
    Source:
    OSV source · Advisory

Latest release

No releases recorded for this line.

Should I use this version?

Not recommended for new deployments

Upgrade to a currently supported release line. Recommended target: Django 6.1.

Upgrade from 3.0

Recommended target: Django 6.1

Version comparison

Compact comparison against the nearest relevant release lines.

3.06.1
Statusend of lifestandard support
Latest release6.1
EOLApr 2021Dec 2027
Riskhighlow

Sources

Where this information comes from.

Lifecycle sources

Release sources

Data coverage

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Releases tracked
0
Lifecycle periods
3
EOL
Known
Provenance records
4
Data last checked
30 Aug 2026
Latest source update
30 Aug 2026

Other Django versions