---
title: "Django 4.2.7 release notes"
version: 6.1
locale: fr
source: https://docs.djangoproject.com/fr/6.1/releases/4.2.7/
canonical: https://djangodocs.dev/fr/6.1/releases/4.2.7/
---
# Django 4.2.7 release notes

*November 1, 2023*

Django 4.2.7 fixes a security issue with severity « moderate » and several bugs
in 4.2.6.

## CVE-2023-46695: Potential denial of service vulnerability in `UsernameField` on Windows

The [`NFKC normalization`](https://docs.python.org/3/library/unicodedata.html#unicodedata.normalize) is slow on
Windows. As a consequence, `django.contrib.auth.forms.UsernameField` was
subject to a potential denial of service attack via certain inputs with a very
large number of Unicode characters.

In order to avoid the vulnerability, invalid values longer than
`UsernameField.max_length` are no longer normalized, since they cannot pass
validation anyway.

## Correction de bogues

- Fixed a regression in Django 4.2 that caused a crash of
  `QuerySet.aggregate()` with aggregates referencing expressions containing
  subqueries ([#34798](https://code.djangoproject.com/ticket/34798)).
- Restored, following a regression in Django 4.2, creating
  `varchar/text_pattern_ops` indexes on `CharField` and `TextField` with
  deterministic collations on PostgreSQL ([#34932](https://code.djangoproject.com/ticket/34932)).
