---
title: "Django 4.2.26 リリースノート"
version: 6.0
locale: ja
source: https://docs.djangoproject.com/ja/6.0/releases/4.2.26/
canonical: https://djangodocs.dev/ja/6.0/releases/4.2.26/
---
# Django 4.2.26 リリースノート

*2025年11月5日*

Django 4.2.26 fixes one security issue with severity "high" and one security
issue with severity "moderate" in 4.2.25.

## CVE-2025-64458: Potential denial-of-service vulnerability in `HttpResponseRedirect` and `HttpResponsePermanentRedirect` on Windows

Python's [`NFKC normalization`](https://docs.python.org/3/library/unicodedata.html#unicodedata.normalize) is slow on
Windows. As a consequence, [`HttpResponseRedirect`](/ja/6.0/ref/request-response/#django.http.HttpResponseRedirect),
[`HttpResponsePermanentRedirect`](/ja/6.0/ref/request-response/#django.http.HttpResponsePermanentRedirect), and the shortcut
[`redirect()`](/ja/6.0/topics/http/shortcuts/#django.shortcuts.redirect) were subject to a potential
denial-of-service attack via certain inputs with a very large number of Unicode
characters (follow up to [**CVE 2025-27556**](https://www.cve.org/CVERecord?id=CVE-2025-27556)).

## CVE-2025-64459: Potential SQL injection via `_connector` keyword argument

[`QuerySet.filter()`](/ja/6.0/ref/models/querysets/#django.db.models.query.QuerySet.filter), [`exclude()`](/ja/6.0/ref/models/querysets/#django.db.models.query.QuerySet.exclude), [`get()`](/ja/6.0/ref/models/querysets/#django.db.models.query.QuerySet.get),
and [`Q`](/ja/6.0/ref/models/querysets/#django.db.models.Q) were subject to SQL injection using a suitably crafted
dictionary, with dictionary expansion, as the `_connector` argument.
