Visit NES for Django Home Page
NES for Django 3.2.x Release Notes
3 versions
Comprehensive release notes and changelog for NES for Django 3.2.x, including security patches, bug fixes, and feature updates across all supported versions.
April 2026
3.2.27
Released Apr 29, 2026 Full Version:
3.2.27
Notes
- Full Version:
nes/django@3.2.27
Security Fixes
- contrib:
- admin: Privilege abuse in
ModelAdmin.list_editable.- This fixes a low-severity Privilege abuse in
ModelAdmin.list_editable. vulnerability CVE-2026-4292.
- This fixes a low-severity Privilege abuse in
- auth: Username enumeration through timing difference in
mod_wsgiAuthentication handler.- This fixes a low-severity Authentication vulnerability CVE-2025-13473.
- contenttypes: Privilege abuse in
GenericInlineModelAdmin.- This fixes a low-severity Privilege abuse in
ModelAdmin.list_editable. vulnerability (CVE-2026-4277).
- This fixes a low-severity Privilege abuse in
- gis: Potential SQL injection via raster lookups on PostGIS.
- This fixes a high-severity SQL injection vulnerability CVE-2026-1207.
- admin: Privilege abuse in
- core/cache: Potential incorrect permissions on newly created file system objects.
- This fixes a low-severity Broken Access Control vulnerability CVE-2026-25674.
- core/handlers:
- Potential denial-of-service vulnerability via repeated headers when using ASGI.
- This fixes a medium-severity denial-of-service (DoS) vulnerability CVE-2025-14550.
- ASGI header spoofing via underscore/hyphen conflation.
- This fixes a medium-severity Authentication vulnerability CVE-2026-3902.
- Potential denial-of-service vulnerability via repeated headers when using ASGI.
- db/models:
- Potential SQL injection via
QuerySet.order_byandFilteredRelation.- This fixes a high-severity SQL injection vulnerability CVE-2026-1312.
- Potential SQL injection in column aliases via control characters.
- This fixes a high-severity SQL injection vulnerability CVE-2026-1287.
- Potential SQL injection via
- files/storage: Potential incorrect permissions on newly created file system objects.
- This fixes a low-severity Broken Access Control vulnerability CVE-2026-25674.
- forms: Potential denial-of-service vulnerability in
URLFieldvia Unicode normalization on Windows.- This fixes a medium-severity denial-of-service (DoS) vulnerability CVE-2026-25673.
- http:
- multipartparser: Potential denial-of-service vulnerability in
MultiPartParservia base64-encoded file upload- This fixes a medium-severity Denial of Service (DoS) vulnerability CVE-2026-33033.
- request: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass.
- This fixes a high-severity Denial of Service (DoS) vulnerability CVE-2026-33034.
- multipartparser: Potential denial-of-service vulnerability in
- utils:
- Potential denial-of-service vulnerability in
django.utils.text.TruncatorHTML methods.- This fixes a medium-severity denial-of-service (DoS) vulnerability CVE-2026-1285.
- Potential incorrect permissions on newly created file system objects.
- This fixes a low-severity Broken Access Control vulnerability CVE-2026-25674.
- Potential denial-of-service vulnerability in
January 2026
3.2.26
Released Jan 9, 2026Notes
- Full package name and version:
nes/django@3.2.26
Security Fixes
- db/models: Prevented SQL injections in Q/QuerySet via the _connector kwarg.
December 2025
3.2.25+trial
Released Dec 16, 2025Stay in the loop
~/herodevs-spring-framework-support
herodevs@nes:open-source$ ./display-support-info.sh