---
title: "Django 3.2.19 release notes"
version: 4.2
locale: pt-br
source: https://docs.djangoproject.com/pt-br/4.2/releases/3.2.19/
canonical: https://djangodocs.dev/pt-br/4.2/releases/3.2.19/
---
# Django 3.2.19 release notes

*May 3, 2023*

Django 3.2.19 fixes a security issue with severity “low” in 3.2.18.

## CVE-2023-31047: Potential bypass of validation when uploading multiple files using one form field

Uploading multiple files using one form field has never been supported by
[`forms.FileField`](/pt-br/4.2/ref/forms/fields/#django.forms.FileField) or [`forms.ImageField`](/pt-br/4.2/ref/forms/fields/#django.forms.ImageField) as only the last
uploaded file was validated. Unfortunately, [Enviando múltiplos arquivos](/pt-br/4.2/topics/http/file-uploads/#uploading-multiple-files)
topic suggested otherwise.

In order to avoid the vulnerability, [`ClearableFileInput`](/pt-br/4.2/ref/forms/widgets/#django.forms.ClearableFileInput)
and [`FileInput`](/pt-br/4.2/ref/forms/widgets/#django.forms.FileInput) form widgets now raise `ValueError` when
the `multiple` HTML attribute is set on them. To prevent the exception and
keep the old behavior, set `allow_multiple_selected` to `True`.

For more details on using the new attribute and handling of multiple files
through a single field, see [Enviando múltiplos arquivos](/pt-br/4.2/topics/http/file-uploads/#uploading-multiple-files).
