1. ===========================
    
  2. Django 3.1.14 release notes
    
  3. ===========================
    
  4. 
    
  5. *December 7, 2021*
    
  6. 
    
  7. Django 3.1.14 fixes a security issue with severity "low" in 3.1.13.
    
  8. 
    
  9. CVE-2021-44420: Potential bypass of an upstream access control based on URL paths
    
  10. =================================================================================
    
  11. 
    
  12. HTTP requests for URLs with trailing newlines could bypass an upstream access
    
  13. control based on URL paths.