---
title: "Django 2.2.22 release notes"
version: 4.2
locale: el
source: https://docs.djangoproject.com/el/4.2/releases/2.2.22/
canonical: https://djangodocs.dev/el/4.2/releases/2.2.22/
---
# Django 2.2.22 release notes

*May 6, 2021*

Django 2.2.22 fixes a security issue in 2.2.21.

## CVE-2021-32052: Header injection possibility since `URLValidator` accepted newlines in input on Python 3.9.5+

On Python 3.9.5+, [`URLValidator`](/el/4.2/ref/validators/#django.core.validators.URLValidator) didn’t prohibit
newlines and tabs. If you used values with newlines in HTTP response, you could
suffer from header injection attacks. Django itself wasn’t vulnerable because
[`HttpResponse`](/el/4.2/ref/request-response/#django.http.HttpResponse) prohibits newlines in HTTP headers.

Moreover, the `URLField` form field which uses `URLValidator` silently
removes newlines and tabs on Python 3.9.5+, so the possibility of newlines
entering your data only existed if you are using this validator outside of the
form fields.

This issue was introduced by the [bpo-43882](https://bugs.python.org/issue?@action=redirect&bpo=43882) fix.
