Django 3.2 LTS
Current status
Django 3.2 reached end of life on 1 Apr 2024. Security and bug fixes are no longer provided by the project according to published lifecycle data.
Official lifecycle source: Django Download / Support Schedule
- Support phase
- end of life
- End of life
- 1 Apr 2024
- Latest release
- —
- Released
- —
At a glance
- Version line
- 3.2
- Initial release
- —
- Lifecycle phase
- end of life
- Latest stable
- —
- Latest release date
- —
- EOL
- 1 Apr 2024
- Risk
- high
- Releases tracked
- 0
Lifecycle timeline
Phases from published LifecyclePeriod records. Missing phases are not inferred.
extended support
7 Dec 2021 → 1 Apr 2024
Source: Django Download / Support Schedule
end of lifecurrent
1 Apr 2024 → —
Source: Django Download / Support Schedule
standard support
— → 7 Dec 2021
Source: Django Download / Support Schedule
Django 3.2 reached end of life on 1 Apr 2024. Security and bug fixes are no longer provided by the project according to published lifecycle data.
Security
Advisories affecting Django 3.2 (OSV.dev evidence). Known exploited status from CISA KEV when matched.
- Known vulnerabilities
- 15
- Known exploited
- 0
- Highest CVSS
- 9.8
- CVE-2023-31047GHSA-r3xc-prgr-mg9p
Django bypasses validation when using one form field to upload multiple files
- CVSS:
- 9.8 (critical) · NVD
- CWE:
- CWE-20, CWE-862
- Affected:
- >=3.2a1,<3.2.19
- Fixed in:
- 3.2.19
- Source:
- OSV source · Advisory
- CVE-2022-28346GHSA-2gwj-7jmv-h26r
SQL Injection in Django
- CVSS:
- 9.8 (critical) · NVD
- CWE:
- CWE-89
- Affected:
- >=3.2,<3.2.13
- Fixed in:
- 3.2.13
- Source:
- OSV source · Advisory
- CVE-2022-28347GHSA-w24h-v9qh-8gxj
SQL Injection in Django
- CVSS:
- 9.8 (critical) · NVD
- CWE:
- CWE-89
- Affected:
- >=3.2,<3.2.13
- Fixed in:
- 3.2.13
- Source:
- OSV source · Advisory
- CVE-2025-64459GHSA-frmv-pr5f-9mcr
Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
- CVSS:
- 9.1 (critical) · NVD
- CWE:
- CWE-89
- Affected:
- <4.2.26
- Fixed in:
- 4.2.26
- Source:
- OSV source · Advisory
- CVE-2022-36359GHSA-8x94-hmjh-97hq
Django vulnerable to Reflected File Download attack
- CVSS:
- 8.8 (high) · NVD
- CWE:
- CWE-494
- Affected:
- <3.2.15
- Fixed in:
- 3.2.15
- Source:
- OSV source · Advisory
- CVE-2025-57833GHSA-6w2r-r2m5-xq5w
Django is subject to SQL injection through its column aliases
- CVSS:
- 8.1 (high) · NVD
- CWE:
- CWE-89
- Affected:
- <4.2.24
- Fixed in:
- 4.2.24
- Source:
- OSV source · Advisory
- CVE-2025-64458GHSA-qw25-v68c-qjf3
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-407
- Affected:
- <4.2.26
- Fixed in:
- 4.2.26
- Source:
- OSV source · Advisory
- CVE-2024-24680GHSA-xxj9-f6rv-m3x4
Django denial-of-service attack in the intcomma template filter
- CVSS:
- 7.5 (high) · NVD
- Affected:
- >=3.2,<3.2.24
- Fixed in:
- 3.2.24
- Source:
- OSV source · Advisory
- CVE-2023-43665GHSA-h8gc-pgj2-vjm3
Django Denial-of-service in django.utils.text.Truncator
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-1284
- Affected:
- >=3.2a1,<3.2.22
- Fixed in:
- 3.2.22
- Source:
- OSV source · Advisory
- CVE-2023-41164GHSA-7h4p-27mh-hmrw
Django Denial of service vulnerability in django.utils.encoding.uri_to_iri
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-1284
- Affected:
- >=3.2,<3.2.21
- Fixed in:
- 3.2.21
- Source:
- OSV source · Advisory
- CVE-2023-46695GHSA-qmf9-6jqf-j8fq
Django potential denial of service vulnerability in UsernameField on Windows
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-770
- Affected:
- >=3.2a1,<3.2.23
- Fixed in:
- 3.2.23
- Source:
- OSV source · Advisory
- CVE-2023-36053GHSA-jh3w-4vvf-mjgr
Django has regular expression denial of service vulnerability in EmailValidator/URLValidator
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-1333
- Affected:
- >=3.2a1,<3.2.20
- Fixed in:
- 3.2.20
- Source:
- OSV source · Advisory
- CVE-2023-36053PYSEC-2023-100
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-1333
- Affected:
- >=3.2,<3.2.20
- Fixed in:
- 3.2.20
- Source:
- OSV source · Advisory
- CVE-2023-24580GHSA-2hrw-hx67-34x6
Resource exhaustion in Django
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-400
- Affected:
- >=3.2a1,<3.2.18
- Fixed in:
- 3.2.18
- Source:
- OSV source · Advisory
- CVE-2023-23969GHSA-q2jf-h9jm-m7p4
Django contains Uncontrolled Resource Consumption via cached header
- CVSS:
- 7.5 (high) · NVD
- CWE:
- CWE-770
- Affected:
- >=3.2a1,<3.2.17
- Fixed in:
- 3.2.17
- Source:
- OSV source · Advisory
Latest release
No releases recorded for this line.
Should I use this version?
Not recommended for new deployments
Upgrade to a currently supported release line. Recommended target: Django 6.1.
Upgrade from 3.2
Recommended target: Django 6.1
Version comparison
Compact comparison against the nearest relevant release lines.
Sources
Where this information comes from.
Lifecycle sources
- Django Download / Support Schedulefirst party · high confidence
Official source: https://www.djangoproject.com/download/
Last verified 30 Aug 2026
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Verification time not recorded
- OSV.devfirst party
Official source: https://osv.dev
Verification time not recorded
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Verification time not recorded
- PyPI JSON APIfirst party
Official source: https://pypi.org
Verification time not recorded
Release sources
- Django Download / Support Schedulefirst party · high confidence
Official source: https://www.djangoproject.com/download/
Last verified 30 Aug 2026
Data coverage
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Releases tracked
- 0
- Lifecycle periods
- 3
- EOL
- Known
- Provenance records
- 4
- Data last checked
- 30 Aug 2026
- Latest source update
- 30 Aug 2026
