Django 5.2.3 release notes¶
June 10, 2025
Django 5.2.3 fixes several bugs in 5.2.2. Also, the latest string translations from Transifex are incorporated.
Bugfixes¶
Fixed a log injection possibility by migrating remaining response logging to
django.utils.log.log_response()
, which safely escapes arguments such as the request path to prevent unsafe log output (CVE 2025-48432).Fixed a regression in Django 5.2 that caused
QuerySet.bulk_update()
to incorrectly convertNone
to JSONnull
instead of SQLNULL
forJSONField
(#36419).