September 4, 2023
Django 4.2.5 fixes a security issue with severity “moderate” and several bugs in 4.2.4.
django.utils.encoding.uri_to_iri() was subject to potential denial of
service attack via certain inputs with a very large number of Unicode
Fixed a regression in Django 4.2 that caused an incorrect validation of
__isnull lookups against
Fixed a bug in Django 4.2 where the deprecated
STATICFILES_STORAGE settings were not synced with
Fixed a regression in Django 4.2.2 that caused an unnecessary selection of a
ManyToManyField without a natural key during serialization
Fixed a regression in Django 4.2 that caused a crash of a queryset when
filtering against deeply nested
OuterRef() annotations (#34803).