---
title: "Django 5.2.8 release notes"
version: 5.2
locale: id
source: https://docs.djangoproject.com/id/5.2/releases/5.2.8/
canonical: https://djangodocs.dev/id/5.2/releases/5.2.8/
---
# Django 5.2.8 release notes

*November 5, 2025*

Django 5.2.8 fixes one security issue with severity "high", one security issue
with severity "moderate", and several bugs in 5.2.7. It also adds compatibility
with Python 3.14.

## CVE-2025-64458: Potential denial-of-service vulnerability in `HttpResponseRedirect` and `HttpResponsePermanentRedirect` on Windows

Python's [`NFKC normalization`](https://docs.python.org/3/library/unicodedata.html#unicodedata.normalize) is slow on
Windows. As a consequence, [`HttpResponseRedirect`](/id/5.2/ref/request-response/#django.http.HttpResponseRedirect),
[`HttpResponsePermanentRedirect`](/id/5.2/ref/request-response/#django.http.HttpResponsePermanentRedirect), and the shortcut
[`redirect()`](/id/5.2/topics/http/shortcuts/#django.shortcuts.redirect) were subject to a potential
denial-of-service attack via certain inputs with a very large number of Unicode
characters (follow up to [**CVE 2025-27556**](https://www.cve.org/CVERecord?id=CVE-2025-27556)).

## CVE-2025-64459: Potential SQL injection via `_connector` keyword argument

[`QuerySet.filter()`](/id/5.2/ref/models/querysets/#django.db.models.query.QuerySet.filter), [`exclude()`](/id/5.2/ref/models/querysets/#django.db.models.query.QuerySet.exclude), [`get()`](/id/5.2/ref/models/querysets/#django.db.models.query.QuerySet.get),
and [`Q`](/id/5.2/ref/models/querysets/#django.db.models.Q) were subject to SQL injection using a suitably crafted
dictionary, with dictionary expansion, as the `_connector` argument.

## Perbaikan kesalahan

- Added compatibility for `oracledb` 3.4.0 ([#36646](https://code.djangoproject.com/ticket/36646)).
- Fixed a bug in Django 5.2 where `QuerySet.first()` and `QuerySet.last()`
  raised an error on querysets performing aggregation that selected all fields
  of a composite primary key ([#36648](https://code.djangoproject.com/ticket/36648)).
- Fixed a bug in Django 5.2 where proxy models having a `CompositePrimaryKey`
  incorrectly raised a `models.E042` system check error ([#36704](https://code.djangoproject.com/ticket/36704)).
