<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/django-security-releases-issued-6-1-2-6-0-9-and-5-2-18-jyxwr9azv" -->

---
title: Django security releases issued: 6.1.2, 6.0.9, and 5.2.18
description: Django released versions 6.1.2, 6.0.9, and 5.2.18 to fix four security issues: a low-severity DoS in get_supported_language_variant() from unbounded language...
canonical: https://daily.dev/posts/django-security-releases-issued-6-1-2-6-0-9-and-5-2-18-jyxwr9azv
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Django security releases issued: 6.1.2, 6.0.9, and 5.2.18 | daily.dev
og:description: Django released versions 6.1.2, 6.0.9, and 5.2.18 to fix four security issues: a low-severity DoS in get_supported_language_variant() from unbounded language...
og:url: https://daily.dev/posts/django-security-releases-issued-6-1-2-6-0-9-and-5-2-18-jyxwr9azv
og:image: https://api.daily.dev/og/posts/JYxWr9AzV.png
og:image:alt: Django security releases issued: 6.1.2, 6.0.9, and 5.2.18
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Django security releases issued: 6.1.2, 6.0.9, and 5.2.18

**[Django](https://daily.dev/sources/django)** · 4 min read · 1 upvotes · 0 comments

## Summary

Django released versions 6.1.2, 6.0.9, and 5.2.18 to fix four security issues: a low-severity DoS in get_supported_language_variant() from unbounded language code caching, a moderate DoS in HTTP header parsing due to quadratic time complexity (now using Python's email.message.Message), a moderate request-forgery issue allowing GDAL to make network requests via unwrapped raster bytes in spatial lookups (a backward-incompatible fix requiring explicit GDALRaster wrapping), and a moderate privilege-abuse bug letting forged POST data delete or create instances in model formsets with editable primary keys. All supported branches (main, 6.1, 6.0, 5.2) received patches, and users are urged to upgrade immediately.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.djangoproject.com/weblog/2026/oct/06/security-releases>

## Questions this post answers

### What does CVE-2026-87890 in Django's spatial lookups affect and is it a breaking change?

CVE-2026-87890 is a moderate-severity request forgery issue where raster values passed as raw bytes to spatial lookups could contain a VRT document referencing an external source, causing GDAL to issue network requests as the Django process user. Fixed in Django 6.1.2, 6.0.9, and 5.2.18, the fix is backward incompatible: byte values must now be explicitly wrapped in GDALRaster before use in spatial lookups, though valid hexadecimal geometry bytes are still accepted.

_Teams running GIS-enabled Django apps can track breaking security fixes like this one on daily.dev before upgrading._

### Why was Django's parse_header_parameters() function vulnerable to denial-of-service attacks?

django.utils.http.parse_header_parameters() had quadratic time complexity when parsing values with many separators inside a quoted parameter, reachable by unauthenticated requests through headers like Accept or Content-Type via HttpRequest.accepts(). Fixed in Django 6.1.2, 6.0.9, and 5.2.18 (CVE-2026-84429, moderate severity) by switching to Python's email.message.Message for parsing, which also changes how some malformed RFC 2231 values are decoded.

_Developers hardening Django APIs against header-based DoS vectors can follow fixes like this on daily.dev._

### How did forged POST data exploit Django model formsets with editable primary keys?

Model formsets with an editable primary key, such as a OneToOneField, natural key, or UUID primary key, allowed forged POST data to delete instances outside the limiting queryset or create instances through edit-only formsets. Models using the default BigAutoField primary key were unaffected. This moderate-severity issue (CVE-2026-87975) is fixed in Django 6.1.2, 6.0.9, and 5.2.18.

_Django developers auditing formset security can keep up with fixes like this via daily.dev._

## Similar posts on daily.dev

- [Django Security Fixes, Python Releases, and New Tools](https://daily.dev/posts/django-security-fixes-python-releases-and-new-tools-xiycsmntw) · Django News · 0 upvotes · 0 comments
- [Issue 340: Django security releases 6.0.6 and 5.2.15](https://daily.dev/posts/issue-340-django-security-releases-6-0-6-and-5-2-15-0r7w6h8w1) · Django News · 0 upvotes · 0 comments
- [Django bugfix release issued: 6.1.1](https://daily.dev/posts/django-bugfix-release-issued-6-1-1-k0yavwjgz) · Django · 7 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#python](https://daily.dev/tags/python), [#django](https://daily.dev/tags/django), [#web-security](https://daily.dev/tags/web-security)

[View this post on daily.dev](https://daily.dev/posts/django-security-releases-issued-6-1-2-6-0-9-and-5-2-18-jyxwr9azv)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Django security releases issued: 6.1.2, 6.0.9, and 5.2.18","url":"https://daily.dev/posts/django-security-releases-issued-6-1-2-6-0-9-and-5-2-18-jyxwr9azv","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/django-security-releases-issued-6-1-2-6-0-9-and-5-2-18-jyxwr9azv"},"datePublished":"2026-10-06T13:32:32.298Z","dateModified":"2026-10-06T13:35:14.268Z","description":"Django released versions 6.1.2, 6.0.9, and 5.2.18 to fix four security issues: a low-severity DoS in get_supported_language_variant() from unbounded language...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/71538c3530bf6c6bbacb396cf5ffc721?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/71538c3530bf6c6bbacb396cf5ffc721?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Django","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Django","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/4a658d547a52423e99fe641ecc576195","url":"https://daily.dev/sources/django"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/django-security-releases-issued-6-1-2-6-0-9-and-5-2-18-jyxwr9azv","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cyber,python,django,web-security","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Django","item":"https://daily.dev/sources/django"},{"@type":"ListItem","position":3,"name":"Django security releases issued: 6.1.2, 6.0.9, and 5.2.18"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/django-security-releases-issued-6-1-2-6-0-9-and-5-2-18-jyxwr9azv#faq","mainEntity":[{"@type":"Question","name":"What does CVE-2026-87890 in Django's spatial lookups affect and is it a breaking change?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-87890 is a moderate-severity request forgery issue where raster values passed as raw bytes to spatial lookups could contain a VRT document referencing an external source, causing GDAL to issue network requests as the Django process user. Fixed in Django 6.1.2, 6.0.9, and 5.2.18, the fix is backward incompatible: byte values must now be explicitly wrapped in GDALRaster before use in spatial lookups, though valid hexadecimal geometry bytes are still accepted. Teams running GIS-enabled Django apps can track breaking security fixes like this one on daily.dev before upgrading."}},{"@type":"Question","name":"Why was Django's parse_header_parameters() function vulnerable to denial-of-service attacks?","acceptedAnswer":{"@type":"Answer","text":"django.utils.http.parse_header_parameters() had quadratic time complexity when parsing values with many separators inside a quoted parameter, reachable by unauthenticated requests through headers like Accept or Content-Type via HttpRequest.accepts(). Fixed in Django 6.1.2, 6.0.9, and 5.2.18 (CVE-2026-84429, moderate severity) by switching to Python's email.message.Message for parsing, which also changes how some malformed RFC 2231 values are decoded. Developers hardening Django APIs against header-based DoS vectors can follow fixes like this on daily.dev."}},{"@type":"Question","name":"How did forged POST data exploit Django model formsets with editable primary keys?","acceptedAnswer":{"@type":"Answer","text":"Model formsets with an editable primary key, such as a OneToOneField, natural key, or UUID primary key, allowed forged POST data to delete instances outside the limiting queryset or create instances through edit-only formsets. Models using the default BigAutoField primary key were unaffected. This moderate-severity issue (CVE-2026-87975) is fixed in Django 6.1.2, 6.0.9, and 5.2.18. Django developers auditing formset security can keep up with fixes like this via daily.dev."}}]}
```

