---
title: "Django 5.2.14 release notes"
version: dev
locale: en
source: https://docs.djangoproject.com/en/dev/releases/5.2.14/
canonical: https://djangodocs.dev/en/dev/releases/5.2.14/
---
# Django 5.2.14 release notes

*May 5, 2026*

Django 5.2.14 fixes three security issues with severity “low” in 5.2.13.

## CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass

ASGI requests with a missing or understated `Content-Length` header could
bypass the [`FILE_UPLOAD_MAX_MEMORY_SIZE`](/en/dev/ref/settings/#std-setting-FILE_UPLOAD_MAX_MEMORY_SIZE) limit, potentially loading
large files into memory and causing service degradation.

As a reminder, Django [expects a limit to be configured](/en/dev/topics/security/#user-uploaded-content-security) at the web server level rather than solely
relying on [`FILE_UPLOAD_MAX_MEMORY_SIZE`](/en/dev/ref/settings/#std-setting-FILE_UPLOAD_MAX_MEMORY_SIZE).

This issue has severity “low” according to the [Django security policy](/en/dev/internals/security/#severity-levels).

## CVE-2026-35192: Session fixation via public cached pages and `SESSION_SAVE_EVERY_REQUEST`

Response headers did not [vary on](/en/dev/topics/cache/#using-vary-headers) cookies if a
session was not modified, but [`SESSION_SAVE_EVERY_REQUEST`](/en/dev/ref/settings/#std-setting-SESSION_SAVE_EVERY_REQUEST) was
`True`. A remote attacker could steal a user’s session after that user visits
a cached public page.

This issue has severity “low” according to the [Django security policy](/en/dev/internals/security/#severity-levels).

## CVE-2026-6907: Potential exposure of private data due to incorrect handling of `Vary: *` in `UpdateCacheMiddleware`

Previously, [`UpdateCacheMiddleware`](/en/dev/ref/middleware/#django.middleware.cache.UpdateCacheMiddleware) would
erroneously cache requests where the `Vary` header contained an asterisk
(`'*'`). This could lead to private data being stored and served.

This issue has severity “low” according to the [Django security policy](/en/dev/internals/security/#severity-levels).
