Django 5.1.8 リリースノート¶
2025年4月2日
Django 5.1.8 では、 5.1.7 における深刻度 "moderate" のセキュリティの問題1件と、いくつかのバグを修正しました。
CVE-2025-27556: Windows における、 LoginView 、 LogoutView および set_language() での潜在的な DoS 攻撃の脆弱性¶
Python's NFKC normalization is slow on
Windows. As a consequence, LoginView,
LogoutView, and
set_language() were subject to a potential
denial-of-service attack via certain inputs with a very large number of Unicode
characters.
バグ修正¶
Fixed a regression in Django 5.1.7 where the removal of the
single_objectparameter unintentionally altered the signature and return type ofLogEntryManager.log_actions()(#36234).