summaryrefslogtreecommitdiff
path: root/docs
AgeCommit message (Collapse)Author
2025-10-01[5.1.x] Fixed CVE-2025-59682 -- Fixed potential partial directory-traversal ↵Sarah Boyce
via archive.extract(). Thanks stackered for the report. Follow up to 05413afa8c18cdb978fcdf470e09f7a12b234a23. Backport of 924a0c092e65fa2d0953fd1855d2dc8786d94de2 from main.
2025-10-01[5.1.x] Fixed CVE-2025-59681 -- Protected QuerySet.annotate(), alias(), ↵Mariusz Felisiak
aggregate(), and extra() against SQL injection in column aliases on MySQL/MariaDB. Thanks sw0rd1ight for the report. Follow up to 93cae5cb2f9a4ef1514cf1a41f714fef08005200. Backport of 41b43c74bda19753c757036673ea9db74acf494a from main.
2025-09-24[5.1.x] Added stub release notes and release date for 5.1.13 and 4.2.25.Mariusz Felisiak
Backport of 00174507f8a91e9577ae233c58af561b379f2695 from main.
2025-09-04[5.1.x] Added missing backticks in docs/releases/security.txt.Mariusz Felisiak
Backport of 686a8a62ae7faba9c3b17080c3532b821e8cb1f3 from main
2025-09-03[5.1.x] Added CVE-2025-57833 to security archive.Sarah Boyce
Backport of f0c05a40d27d69ef3a7b4e5e0199b5dba5b11feb from main.
2025-09-03[5.1.x] Fixed CVE-2025-57833 -- Protected FilteredRelation against SQL ↵Jake Howard
injection in column aliases. Thanks Eyal Gabay (EyalSec) for the report. Backport of 51711717098d3f469f795dfa6bc3758b24f69ef7 from main.
2025-08-27[5.1.x] Added stub release notes and release date for 5.1.12 and 4.2.24.Sarah Boyce
Backport of 4c71e334401a3e83c013419d0e2211543e7e873b from main.
2025-08-04[5.1.x] Refs #36535 -- Doc'd that docutils < 0.22 is required.Natalia
2025-06-10[5.1.x] Added follow-up to CVE-2025-48432 to security archive.Sarah Boyce
Backport of 2714bc3f2c8675d32caae764c874ac381c836c7f from main.
2025-06-06[5.1.x] Refs CVE-2025-48432 -- Prevented log injection in remaining response ↵Jake Howard
logging. Migrated remaining response-related logging to use the `log_response()` helper to avoid potential log injection, to ensure untrusted values like request paths are safely escaped. Co-authored-by: Natalia <124304+nessita@users.noreply.github.com> Backport of 957951755259b412d5113333b32bf85871d29814 from main.
2025-06-04[5.1.x] Added CVE-2025-48432 to security archive.Natalia
Backport of 51923c576a596ad00214e44028f9dee9748bce95 from main.
2025-06-04[5.1.x] Fixed CVE-2025-48432 -- Escaped formatting arguments in ↵Natalia
`log_response()`. Suitably crafted requests containing a CRLF sequence in the request path may have allowed log injection, potentially corrupting log files, obscuring other attacks, misleading log post-processing tools, or forging log entries. To mitigate this, all positional formatting arguments passed to the logger are now escaped using "unicode_escape" encoding. Thanks to Seokchan Yoon (https://ch4n3.kr/) for the report. Co-authored-by: Carlton Gibson <carlton@noumenal.es> Co-authored-by: Jake Howard <git@theorangeone.net> Backport of a07ebec5591e233d8bbb38b7d63f35c5479eef0e from main.
2025-05-28[5.1.x] Added stub release notes and release date for 5.1.10 and 4.2.22.Natalia
Backport of 1a744343999c9646912cee76ba0a2fa6ef5e6240 from main.
2025-05-26[5.1.x] Fixed #36402, Refs #35980 -- Updated built package name in reusable ↵Jason Judkins
apps tutorial for PEP 625. Backport of 1307b8a1cb05762147736d0f347792b33f645390 from main.
2025-05-09[5.1.x] Refs #35980 -- Added release note about changes in release artifacts ↵Natalia
filenames. Backport of 42ab99309d347f617d60751c2e8d627fb2963049 from main.
2025-05-09[5.1.x] Removed "Expected" from release date for 5.1.9 and 4.2.21.Natalia
Backport of c86156378db09e68db3a9ae1c108f661a67e3abe from main.
2025-05-07[5.1.x] Cleaned up CVE-2025-32873 security archive description.Natalia
Backport of 37f2a77c729ccb71059c8e66c49b07499d2edf60 from main.
2025-05-07[5.1.x] Added CVE-2025-32873 to security archive.Natalia
Backport of fdabda4e05587347aeb3382a442d7e77c1a0c3e5 from main.
2025-05-06[5.1.x] Fixed CVE-2025-32873 -- Mitigated potential DoS in strip_tags().Sarah Boyce
Thanks to Elias Myllymäki for the report, and Shai Berger and Jake Howard for the reviews. Co-authored-by: Natalia <124304+nessita@users.noreply.github.com> Backport of 9f3419b519799d69f2aba70b9d25abe2e70d03e0 from main.
2025-04-30[5.1.x] Added upcoming security release to release notes.Natalia
Backport of 0f5dd0dff3049189a3fe71a62670b746543335d5 from main.
2025-04-23[5.1.x] Refs #36341 -- Added release notes for 5.1.9 and 4.2.21 for fix in ↵nessita
wordwrap template filter. Revision 1e9db35836d42a3c72f3d1015c2f302eb6fee046 fixed a regression in 55d89e25f4115c5674cdd9b9bcba2bb2bb6d820b, which also needs to be backported to the stable branches in extended support (5.1.x and 4.2.x). Backport of c86242d61ff81bddbead115c458c1eb532d43b43 from main.
2025-04-12[5.1.x] Fixed #36320 -- Ignored "duplicated_toc_entry" for ePub docs build.Baptiste Mispelon
Backport of ac16d2876da296d8e50450bf7d776f92d1e16b0d from main
2025-04-07[5.1.x] Fixed #36298 -- Truncated the overwritten file content in ↵Sarah Boyce
file_move_safe(). Regression in 58cd4902a71a3695dd6c21dc957f59c333db364c. Thanks Baptiste Mispelon for the report. Backport of 8ad3e80e88201f4c557f6fa79fcfc0f8a0961830 from main.
2025-04-02[5.1.x] Added CVE-2025-27556 to security archive.Sarah Boyce
Backport of b83dab7d8da8d1dd888164de5ed79e88cedcb19b from main.
2025-04-02[5.1.x] Fixed CVE-2025-27556 -- Mitigated potential DoS in ↵Sarah Boyce
url_has_allowed_host_and_scheme() on Windows. Thank you sw0rd1ight for the report. Backport of 39e2297210d9d2938c75fc911d45f0e863dc4821 from main.
2025-04-02[5.1.x] Fixed #36213 -- Doc'd MySQL's handling of self-select updates in ↵Babak Mahmoudy
QuerySet.update(). Co-authored-by: Andro Ranogajec <ranogaet@gmail.com> Backport of be1b776ad8d6f9bccfbdf63f84b16fb81a13119e from main.
2025-03-31[5.1.x] Clarified pre_delete and post_delete's origin attributes.Clifford Gama
Backport of 9d5d0e8135a9654aa289cf922fcd00ad5e2a7fe5 from main.
2025-03-28[5.1.x] Simplified Intersphinx configuration example.Carlton Gibson
docs.djangoproject.com had been updated to serve the object.inv file from the default location, so the second tuple element can be None (the "default" value). Backport of 5df512e53ab12fd8a0c92421a45aa1b664adb166 from main.
2025-03-27[5.1.x] Doc'd how to use Intersphinx in the reusable apps tutorial.Carlton Gibson
Backport of 6e54e20cc3908d4eb103678db14e1e02e05069dd from main.
2025-03-26[5.1.x] Added stub release notes and release date for 5.1.8 and 5.0.14.Sarah Boyce
Backport of c75fbe843079ca249d7015926490dd21107e63a4 from main.
2025-03-23[5.1.x] Updated ogrinfo output in GIS tutorial.dr-rompecabezas
Backport of fb65c520401d8eefb97725d16608444901cfed14 from main
2025-03-23[5.1.x] Fixed typo in docs/topics/signals.txt.mguegnol
Backport of e2b9a179133ebca9773c5c259f6a7d27489cf141 from main
2025-03-21[5.1.x] Documented the updating of translation catalogs in post-release tasks.Sarah Boyce
Co-authored-by: Natalia <124304+nessita@users.noreply.github.com> Backport of 922c1c732a47c02aa5ef28b0b1a2bd9bc9b92d87 from main.
2025-03-21[5.1.x] Fixed #36095 -- Introduced lazy references in "Models across files" ↵Clifford Gama
section. Backport of 6a2c296e706a0b8f9f9b89e66b37001ce2a03ea7 from main.
2025-03-21[5.1.x] Refs #36095 -- Doc'd that ManyToManyField.through supports lazy ↵Clifford Gama
relationships. Backport of eb4ea9c3efca479b169bed88a5521c4cf47ed2a2 from main.
2025-03-18[5.1.x] Fixed #33497 -- Doc'd that persistent DB connections should be ↵Carlton Gibson
disabled in ASGI and async modes. Backport of 8713e4ae96817a0c7be3f7a8fee25a7c7f819721 from main.
2025-03-18[5.1.x] Fixed #36202 -- Added examples of JSONField __contains and ↵Clifford Gama
__contained_by lookups with nested arrays to docs. Backport of 304e9f3d6ae8387bbfc261d68b51247a1f5230bb from main
2025-03-18[5.1.x] Fixed #36078 -- Doc'd that Postgres normalizes a range field with no ↵Clifford Gama
points to empty. Co-authored-by: Sarah Boyce <42296566+sarahboyce@users.noreply.github.com> Backport of 611e7bc3a0633a35ae3430e359c646e02fa3801d from main.
2025-03-17[5.1.x] Fixed #36254 -- Fixed template dictionary unpacking in ↵YQ
docs/topics/i18n/timezones.txt. Backport of 30e0a43937e685083fa1210c3594678a3b813806 from main.
2025-03-14[5.1.x] Fixed pronoun disagreement in docs/ref/models/querysets.txt.Clifford Gama
Backport of ef6a83789b310a441237a190a493c9586a4cb260 from main.
2025-03-14[5.1.x] Corrected aggregation example in docs/ref/models/querysets.txt.Clifford Gama
Backport of 3235e76eb50be20756f82cb3bbe8e32cc586f7bb from main.
2025-03-12[5.1.x] Fixed #36249 -- Fixed typo in docs/topics/db/queries.txt.hesham hatem
Backport of e03440291b0599934da73b7dfbd2ccf7ec7270d8 from main.
2025-03-12[5.1.x] Fixed #36234 -- Restored single_object argument to ↵Adam Johnson
LogEntry.objects.log_actions(). Thank you Adam Johnson for the report and fix. Thank you Sarah Boyce for your spot on analysis. Regression in c09bceef68e5abb79accedd12dade16aa6577a09, which is partially reverted in this branch. Co-authored-by: Sarah Boyce <42296566+sarahboyce@users.noreply.github.com> Backport of 27b68bcadf1ab2e9f7fd223aed42db352ccdc62d from main.
2025-03-10[5.1.x] Fixed #36066 -- Documented that Q objects can be used directly in ↵samruddhiDharankar
annotations. Backport of 9120a19c4ecb643111b073dd1069e6b410a03c23 from main.
2025-03-06[5.1.x] Added CVE-2025-26699 to security archive.Sarah Boyce
Backport of bad1a18ff28a671f2fdfd447bdf8f43602f882c2 from main.
2025-03-06[5.1.x] Added stub release notes for 5.1.8.Sarah Boyce
Backport of 193e3446e38c5415465608f68620508eace60388 from main.
2025-03-06[5.1.x] Fixed CVE-2025-26699 -- Mitigated potential DoS in wordwrap template ↵Sarah Boyce
filter. Thanks sw0rd1ight for the report. Backport of 55d89e25f4115c5674cdd9b9bcba2bb2bb6d820b from main.
2025-03-05[5.1.x] Fixed typo in docs/ref/checks.txt.hesham942
Backport of 8f942f1c1dbf4222c8ca48253f7959366ed1bb60 from main.
2025-03-05[5.1.x] Fixed #36227 -- Fixed outdated PostgreSQL documentation links.hesham942
Backport of 3ecaa85a247373d7ccbcdd593b3fd4bb701f7674 from main.
2025-03-04[5.1.x] Fixed #36128 -- Clarified auto-generated unique constraint on m2m ↵Clifford Gama
through models. Backport of ae2736ca3bf4c6a27e23ee95530ad965b550d4cc from main.