---
title: "Note di rilascio di Django 2.2.22"
version: 4.1
locale: it
source: https://docs.djangoproject.com/it/4.1/releases/2.2.22/
canonical: https://djangodocs.dev/it/4.1/releases/2.2.22/
---
# Note di rilascio di Django 2.2.22

*6 Maggio 2021*

Django 2.2.22 risolve un problema di sicurezza in 2.2.21.

## CVE-2021-32052: Header injection possibility since `URLValidator` accepted newlines in input on Python 3.9.5+

On Python 3.9.5+, [`URLValidator`](/it/4.1/ref/validators/#django.core.validators.URLValidator) didn’t prohibit
newlines and tabs. If you used values with newlines in HTTP response, you could
suffer from header injection attacks. Django itself wasn’t vulnerable because
[`HttpResponse`](/it/4.1/ref/request-response/#django.http.HttpResponse) prohibits newlines in HTTP headers.

Moreover, the `URLField` form field which uses `URLValidator` silently
removes newlines and tabs on Python 3.9.5+, so the possibility of newlines
entering your data only existed if you are using this validator outside of the
form fields.

This issue was introduced by the [bpo-43882](https://bugs.python.org/issue?@action=redirect&bpo=43882) fix.
