Django 3.2 LTS

Current status

end of lifeLTShigh

Django 3.2 reached end of life on 1 Apr 2024. Security and bug fixes are no longer provided by the project according to published lifecycle data.

Official lifecycle source: Django Download / Support Schedule

Support phase
end of life
End of life
1 Apr 2024
Latest release
Released

At a glance

Version line
3.2
Initial release
Lifecycle phase
end of life
Latest stable
Latest release date
EOL
1 Apr 2024
Risk
high
Releases tracked
0

Lifecycle timeline

Phases from published LifecyclePeriod records. Missing phases are not inferred.

  1. extended support

    7 Dec 2021 → 1 Apr 2024

    Source: Django Download / Support Schedule

  2. end of lifecurrent

    1 Apr 2024 → —

    Source: Django Download / Support Schedule

  3. standard support

    — → 7 Dec 2021

    Source: Django Download / Support Schedule

Django 3.2 reached end of life on 1 Apr 2024. Security and bug fixes are no longer provided by the project according to published lifecycle data.

Security

Advisories affecting Django 3.2 (OSV.dev evidence). Known exploited status from CISA KEV when matched.

Known vulnerabilities
15
Known exploited
0
Highest CVSS
9.8
  • CVE-2023-31047GHSA-r3xc-prgr-mg9p

    Django bypasses validation when using one form field to upload multiple files

    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-20, CWE-862
    Affected:
    >=3.2a1,<3.2.19
    Fixed in:
    3.2.19
    Source:
    OSV source · Advisory
  • CVE-2022-28346GHSA-2gwj-7jmv-h26r

    SQL Injection in Django

    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    >=3.2,<3.2.13
    Fixed in:
    3.2.13
    Source:
    OSV source · Advisory
  • CVE-2022-28347GHSA-w24h-v9qh-8gxj

    SQL Injection in Django

    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    >=3.2,<3.2.13
    Fixed in:
    3.2.13
    Source:
    OSV source · Advisory
  • CVE-2025-64459GHSA-frmv-pr5f-9mcr

    Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.

    CVSS:
    9.1 (critical) · NVD
    CWE:
    CWE-89
    Affected:
    <4.2.26
    Fixed in:
    4.2.26
    Source:
    OSV source · Advisory
  • CVE-2022-36359GHSA-8x94-hmjh-97hq

    Django vulnerable to Reflected File Download attack

    CVSS:
    8.8 (high) · NVD
    CWE:
    CWE-494
    Affected:
    <3.2.15
    Fixed in:
    3.2.15
    Source:
    OSV source · Advisory
  • CVE-2025-57833GHSA-6w2r-r2m5-xq5w

    Django is subject to SQL injection through its column aliases

    CVSS:
    8.1 (high) · NVD
    CWE:
    CWE-89
    Affected:
    <4.2.24
    Fixed in:
    4.2.24
    Source:
    OSV source · Advisory
  • CVE-2025-64458GHSA-qw25-v68c-qjf3

    Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-407
    Affected:
    <4.2.26
    Fixed in:
    4.2.26
    Source:
    OSV source · Advisory
  • CVE-2024-24680GHSA-xxj9-f6rv-m3x4

    Django denial-of-service attack in the intcomma template filter

    CVSS:
    7.5 (high) · NVD
    Affected:
    >=3.2,<3.2.24
    Fixed in:
    3.2.24
    Source:
    OSV source · Advisory
  • CVE-2023-43665GHSA-h8gc-pgj2-vjm3

    Django Denial-of-service in django.utils.text.Truncator

    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-1284
    Affected:
    >=3.2a1,<3.2.22
    Fixed in:
    3.2.22
    Source:
    OSV source · Advisory
  • CVE-2023-41164GHSA-7h4p-27mh-hmrw

    Django Denial of service vulnerability in django.utils.encoding.uri_to_iri

    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-1284
    Affected:
    >=3.2,<3.2.21
    Fixed in:
    3.2.21
    Source:
    OSV source · Advisory
  • CVE-2023-46695GHSA-qmf9-6jqf-j8fq

    Django potential denial of service vulnerability in UsernameField on Windows

    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-770
    Affected:
    >=3.2a1,<3.2.23
    Fixed in:
    3.2.23
    Source:
    OSV source · Advisory
  • CVE-2023-36053GHSA-jh3w-4vvf-mjgr

    Django has regular expression denial of service vulnerability in EmailValidator/URLValidator

    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-1333
    Affected:
    >=3.2a1,<3.2.20
    Fixed in:
    3.2.20
    Source:
    OSV source · Advisory
  • CVE-2023-36053PYSEC-2023-100
    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-1333
    Affected:
    >=3.2,<3.2.20
    Fixed in:
    3.2.20
    Source:
    OSV source · Advisory
  • CVE-2023-24580GHSA-2hrw-hx67-34x6

    Resource exhaustion in Django

    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-400
    Affected:
    >=3.2a1,<3.2.18
    Fixed in:
    3.2.18
    Source:
    OSV source · Advisory
  • CVE-2023-23969GHSA-q2jf-h9jm-m7p4

    Django contains Uncontrolled Resource Consumption via cached header

    CVSS:
    7.5 (high) · NVD
    CWE:
    CWE-770
    Affected:
    >=3.2a1,<3.2.17
    Fixed in:
    3.2.17
    Source:
    OSV source · Advisory

Latest release

No releases recorded for this line.

Should I use this version?

Not recommended for new deployments

Upgrade to a currently supported release line. Recommended target: Django 6.1.

Upgrade from 3.2

Recommended target: Django 6.1

Version comparison

Compact comparison against the nearest relevant release lines.

3.26.1
Statusend of lifestandard support
Latest release6.1
EOLApr 2024Dec 2027
Riskhighlow

Sources

Where this information comes from.

Lifecycle sources

Release sources

Data coverage

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Releases tracked
0
Lifecycle periods
3
EOL
Known
Provenance records
4
Data last checked
30 Aug 2026
Latest source update
30 Aug 2026

Other Django versions