September 4, 2023
Django 4.2.5 fixes a security issue with severity “moderate” and several bugs in 4.2.4.
django.utils.encoding.uri_to_iri()
¶django.utils.encoding.uri_to_iri()
was subject to potential denial of
service attack via certain inputs with a very large number of Unicode
characters.
CheckConstraints
on __isnull
lookups against JSONField
(#34754).DEFAULT_FILE_STORAGE
and
STATICFILES_STORAGE
settings were not synced with STORAGES
(#34773).ManyToManyField
without a natural key during serialization
(#34779).OuterRef()
annotations (#34803).Jan 24, 2024