<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/issue-358-django-6-1-2-6-0-9-and-5-2-18-security-releases-and-djangonaut-space-session-7-pllpujzou" -->

---
title: Issue 358: Django 6.1.2, 6.0.9, and 5.2.18 Security...
description: Django shipped security releases 6.1.2, 6.0.9, and 5.2.18 fixing four CVEs covering denial-of-service risks in language-code lookups and HTTP header parsing, a...
canonical: https://daily.dev/posts/issue-358-django-6-1-2-6-0-9-and-5-2-18-security-releases-and-djangonaut-space-session-7-pllpujzou
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Issue 358: Django 6.1.2, 6.0.9, and 5.2.18 Security Releases and Djangonaut Space Session 7 | daily.dev
og:description: Django shipped security releases 6.1.2, 6.0.9, and 5.2.18 fixing four CVEs covering denial-of-service risks in language-code lookups and HTTP header parsing, a...
og:url: https://daily.dev/posts/issue-358-django-6-1-2-6-0-9-and-5-2-18-security-releases-and-djangonaut-space-session-7-pllpujzou
og:image: https://api.daily.dev/og/posts/pLlpuJZOU.png
og:image:alt: Issue 358: Django 6.1.2, 6.0.9, and 5.2.18 Security Releases and Djangonaut Space Session 7
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Issue 358: Django 6.1.2, 6.0.9, and 5.2.18 Security Releases and Djangonaut Space Session 7

**[Django News](https://daily.dev/sources/djangonews)** · 6 min read · 0 upvotes · 0 comments

## Summary

Django shipped security releases 6.1.2, 6.0.9, and 5.2.18 fixing four CVEs covering denial-of-service risks in language-code lookups and HTTP header parsing, a GDAL raster fetch issue, and a formset vulnerability allowing forged POST data to delete or create model instances; the raster fix requires wrapping bytes in GDALRaster, a backward-incompatible change. Also covered: Django dropping HackerOne for security reports in favor of a dedicated email, Python 3.15.0's surprise third release candidate pushing final release, Djangonaut Space Session 7 kicking off with 28 participants across eight teams, Wagtail pulling core projects from Google Summer of Code 2027 due to low-effort AI-generated PRs, plus community articles, videos, fellow reports, and job listings.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://django-news.com/archive/issue-358-django-612-609-and-5218-security>

## Questions this post answers

### What security vulnerabilities were fixed in Django 6.1.2, 6.0.9, and 5.2.18?

Four CVEs were fixed: denial-of-service risks in language-code lookups and HTTP header parsing, a spatial lookup issue that could make GDAL fetch external rasters, and a model formset vulnerability where editable primary keys combined with forged POST data could delete or create instances. The raster fix requires wrapping raster bytes in GDALRaster, which is a backward-incompatible change requiring code review for GIS applications.

_Track Django security patches like these on daily.dev so upgrades don't catch your GIS code off guard._

### How do I report a security vulnerability in Django now that HackerOne reports are no longer accepted?

New Django security issues should be sent directly to security@djangoproject.com as described in the project's security policy, since Django no longer accepts new reports through HackerOne. Existing HackerOne reports remain open and continue to be handled by the Django Security Team.

_Developers tracking Django's security process can follow updates like this on daily.dev._

### Why did Python 3.15.0 need a third release candidate?

Last-minute lazy-import release blockers forced a surprise third release candidate for Python 3.15.0, pushing the final release to October 9. Maintainers were advised to test and publish 3.15 wheels immediately, since release candidate wheels remain compatible with the final release.

_Developers preparing packages for a new Python release can follow rollout details like this on daily.dev._

## Similar posts on daily.dev

- [Issue 340: Django security releases 6.0.6 and 5.2.15](https://daily.dev/posts/issue-340-django-security-releases-6-0-6-and-5-2-15-0r7w6h8w1) · Django News · 0 upvotes · 0 comments
- [Django Security Fixes, Python Releases, and New Tools](https://daily.dev/posts/django-security-fixes-python-releases-and-new-tools-xiycsmntw) · Django News · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#python](https://daily.dev/tags/python), [#django](https://daily.dev/tags/django)

[View this post on daily.dev](https://daily.dev/posts/issue-358-django-6-1-2-6-0-9-and-5-2-18-security-releases-and-djangonaut-space-session-7-pllpujzou)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Issue 358: Django 6.1.2, 6.0.9, and 5.2.18 Security Releases and Djangonaut Space Session 7","url":"https://daily.dev/posts/issue-358-django-6-1-2-6-0-9-and-5-2-18-security-releases-and-djangonaut-space-session-7-pllpujzou","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/issue-358-django-6-1-2-6-0-9-and-5-2-18-security-releases-and-djangonaut-space-session-7-pllpujzou"},"datePublished":"2026-10-09T10:13:04.045Z","dateModified":"2026-10-09T11:04:30.698Z","description":"Django shipped security releases 6.1.2, 6.0.9, and 5.2.18 fixing four CVEs covering denial-of-service risks in language-code lookups and HTTP header parsing, a...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/a54f4f9246a16acd98af7c29cfbce41b?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/a54f4f9246a16acd98af7c29cfbce41b?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Django News","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Django News","logo":"https://media.daily.dev/image/upload/s--OT_Q8LQ---/f_auto/v1720886573/logos/djangonews","url":"https://daily.dev/sources/djangonews"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/issue-358-django-6-1-2-6-0-9-and-5-2-18-security-releases-and-djangonaut-space-session-7-pllpujzou","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,python,django","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Django News","item":"https://daily.dev/sources/djangonews"},{"@type":"ListItem","position":3,"name":"Issue 358: Django 6.1.2, 6.0.9, and 5.2.18 Security Releases and Djangonaut Space Session 7"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/issue-358-django-6-1-2-6-0-9-and-5-2-18-security-releases-and-djangonaut-space-session-7-pllpujzou#faq","mainEntity":[{"@type":"Question","name":"What security vulnerabilities were fixed in Django 6.1.2, 6.0.9, and 5.2.18?","acceptedAnswer":{"@type":"Answer","text":"Four CVEs were fixed: denial-of-service risks in language-code lookups and HTTP header parsing, a spatial lookup issue that could make GDAL fetch external rasters, and a model formset vulnerability where editable primary keys combined with forged POST data could delete or create instances. The raster fix requires wrapping raster bytes in GDALRaster, which is a backward-incompatible change requiring code review for GIS applications. Track Django security patches like these on daily.dev so upgrades don't catch your GIS code off guard."}},{"@type":"Question","name":"How do I report a security vulnerability in Django now that HackerOne reports are no longer accepted?","acceptedAnswer":{"@type":"Answer","text":"New Django security issues should be sent directly to security@djangoproject.com as described in the project's security policy, since Django no longer accepts new reports through HackerOne. Existing HackerOne reports remain open and continue to be handled by the Django Security Team. Developers tracking Django's security process can follow updates like this on daily.dev."}},{"@type":"Question","name":"Why did Python 3.15.0 need a third release candidate?","acceptedAnswer":{"@type":"Answer","text":"Last-minute lazy-import release blockers forced a surprise third release candidate for Python 3.15.0, pushing the final release to October 9. Maintainers were advised to test and publish 3.15 wheels immediately, since release candidate wheels remain compatible with the final release. Developers preparing packages for a new Python release can follow rollout details like this on daily.dev."}}]}
```

