---
title: "Django 5.2.8 release notes"
version: 6.0
locale: it
source: https://docs.djangoproject.com/it/6.0/releases/5.2.8/
canonical: https://djangodocs.dev/it/6.0/releases/5.2.8/
---
# Django 5.2.8 release notes

*November 5, 2025*

Django 5.2.8 fixes one security issue with severity «high», one security issue
with severity «moderate», and several bugs in 5.2.7. It also adds compatibility
with Python 3.14.

## CVE-2025-64458: Potential denial-of-service vulnerability in `HttpResponseRedirect` and `HttpResponsePermanentRedirect` on Windows

Python’s [`NFKC normalization`](https://docs.python.org/3/library/unicodedata.html#unicodedata.normalize) is slow on
Windows. As a consequence, [`HttpResponseRedirect`](/it/6.0/ref/request-response/#django.http.HttpResponseRedirect),
[`HttpResponsePermanentRedirect`](/it/6.0/ref/request-response/#django.http.HttpResponsePermanentRedirect), and the shortcut
[`redirect()`](/it/6.0/topics/http/shortcuts/#django.shortcuts.redirect) were subject to a potential
denial-of-service attack via certain inputs with a very large number of Unicode
characters (follow up to [**CVE 2025-27556**](https://www.cve.org/CVERecord?id=CVE-2025-27556)).

## CVE-2025-64459: Potential SQL injection via `_connector` keyword argument

[`QuerySet.filter()`](/it/6.0/ref/models/querysets/#django.db.models.query.QuerySet.filter), [`exclude()`](/it/6.0/ref/models/querysets/#django.db.models.query.QuerySet.exclude), [`get()`](/it/6.0/ref/models/querysets/#django.db.models.query.QuerySet.get),
and [`Q`](/it/6.0/ref/models/querysets/#django.db.models.Q) were subject to SQL injection using a suitably crafted
dictionary, with dictionary expansion, as the `_connector` argument.

## Correzioni di bug

- Added compatibility for `oracledb` 3.4.0 ([#36646](https://code.djangoproject.com/ticket/36646)).
- Fixed a bug in Django 5.2 where `QuerySet.first()` and `QuerySet.last()`
  raised an error on querysets performing aggregation that selected all fields
  of a composite primary key ([#36648](https://code.djangoproject.com/ticket/36648)).
- Fixed a bug in Django 5.2 where proxy models having a `CompositePrimaryKey`
  incorrectly raised a `models.E042` system check error ([#36704](https://code.djangoproject.com/ticket/36704)).
