---
title: "Django 4.2.26 release notes"
version: 6.1
locale: it
source: https://docs.djangoproject.com/it/6.1/releases/4.2.26/
canonical: https://djangodocs.dev/it/6.1/releases/4.2.26/
---
# Django 4.2.26 release notes

*November 5, 2025*

Django 4.2.26 fixes one security issue with severity «high» and one security
issue with severity «moderate» in 4.2.25.

## CVE-2025-64458: Potential denial-of-service vulnerability in `HttpResponseRedirect` and `HttpResponsePermanentRedirect` on Windows

Python’s [`NFKC normalization`](https://docs.python.org/3/library/unicodedata.html#unicodedata.normalize) is slow on
Windows. As a consequence, [`HttpResponseRedirect`](/it/6.1/ref/request-response/#django.http.HttpResponseRedirect),
[`HttpResponsePermanentRedirect`](/it/6.1/ref/request-response/#django.http.HttpResponsePermanentRedirect), and the shortcut
[`redirect()`](/it/6.1/topics/http/shortcuts/#django.shortcuts.redirect) were subject to a potential
denial-of-service attack via certain inputs with a very large number of Unicode
characters (follow up to [**CVE 2025-27556**](https://www.cve.org/CVERecord?id=CVE-2025-27556)).

## CVE-2025-64459: Potential SQL injection via `_connector` keyword argument

[`QuerySet.filter()`](/it/6.1/ref/models/querysets/#django.db.models.query.QuerySet.filter), [`exclude()`](/it/6.1/ref/models/querysets/#django.db.models.query.QuerySet.exclude), [`get()`](/it/6.1/ref/models/querysets/#django.db.models.query.QuerySet.get),
and [`Q`](/it/6.1/ref/models/querysets/#django.db.models.Q) were subject to SQL injection using a suitably crafted
dictionary, with dictionary expansion, as the `_connector` argument.
