---
title: "Django 3.2.2 release notes"
version: 4.2
locale: ja
source: https://docs.djangoproject.com/ja/4.2/releases/3.2.2/
canonical: https://djangodocs.dev/ja/4.2/releases/3.2.2/
---
# Django 3.2.2 release notes

*May 6, 2021*

Django 3.2.2 fixes a security issue and a bug in 3.2.1.

## CVE-2021-32052: Header injection possibility since `URLValidator` accepted newlines in input on Python 3.9.5+

On Python 3.9.5+, [`URLValidator`](/ja/4.2/ref/validators/#django.core.validators.URLValidator) didn't prohibit
newlines and tabs. If you used values with newlines in HTTP response, you could
suffer from header injection attacks. Django itself wasn't vulnerable because
[`HttpResponse`](/ja/4.2/ref/request-response/#django.http.HttpResponse) prohibits newlines in HTTP headers.

Moreover, the `URLField` form field which uses `URLValidator` silently
removes newlines and tabs on Python 3.9.5+, so the possibility of newlines
entering your data only existed if you are using this validator outside of the
form fields.

This issue was introduced by the [bpo-43882](https://bugs.python.org/issue?@action=redirect&bpo=43882) fix.

## Bugfixes

- Prevented, following a regression in Django 3.2.1, [`makemigrations`](/ja/4.2/ref/django-admin/#django-admin-makemigrations)
  from generating infinite migrations for a model with `Meta.ordering`
  contained `OrderBy` expressions ([#32714](https://code.djangoproject.com/ticket/32714)).
