---
title: "Django 1.11.22 release notes"
version: 6.0
locale: en
source: https://docs.djangoproject.com/en/6.0/releases/1.11.22/
canonical: https://djangodocs.dev/en/6.0/releases/1.11.22/
---
# Django 1.11.22 release notes

*July 1, 2019*

Django 1.11.22 fixes a security issue in 1.11.21.

## CVE-2019-12781: Incorrect HTTP detection with reverse-proxy connecting via HTTPS

When deployed behind a reverse-proxy connecting to Django via HTTPS,
[`django.http.HttpRequest.scheme`](/en/6.0/ref/request-response/#django.http.HttpRequest.scheme) would incorrectly detect client
requests made via HTTP as using HTTPS. This entails incorrect results for
[`is_secure()`](/en/6.0/ref/request-response/#django.http.HttpRequest.is_secure), and
[`build_absolute_uri()`](/en/6.0/ref/request-response/#django.http.HttpRequest.build_absolute_uri), and that HTTP
requests would not be redirected to HTTPS in accordance with
[`SECURE_SSL_REDIRECT`](/en/6.0/ref/settings/#std-setting-SECURE_SSL_REDIRECT).

`HttpRequest.scheme` now respects [`SECURE_PROXY_SSL_HEADER`](/en/6.0/ref/settings/#std-setting-SECURE_PROXY_SSL_HEADER), if it
is configured, and the appropriate header is set on the request, for both HTTP
and HTTPS requests.

If you deploy Django behind a reverse-proxy that forwards HTTP requests, and
that connects to Django via HTTPS, be sure to verify that your application
correctly handles code paths relying on `scheme`, `is_secure()`,
`build_absolute_uri()`, and `SECURE_SSL_REDIRECT`.
