Skip to content
Brief Security & Trust ·

Django stops taking new security reports through HackerOne

The project now asks researchers to send vulnerability reports by email instead.

In brief
  • Django no longer takes new security reports through HackerOne. Reports now go by email to [email protected].
  • Reports already filed on HackerOne stay open and are still handled by the Django Security Team.

The Django project said on 8 October 2026 that it will no longer take new security reports through HackerOne, a platform where researchers send in vulnerability findings. Anyone who finds a security problem in Django should now email [email protected]. Django pointed readers to its security policies for the full reporting steps. Reports already filed on HackerOne will stay open. The Django Security Team will keep working on them.

Django's notice is short. It does not say why the project dropped HackerOne. It gives no date for when the change took effect. It does not say how many reports are still open on the platform. It also does not say whether the way the team triages or answers reports will change. The notice does not mention rewards or any other change to the security policy beyond the new reporting route.

For teams that build or run software on Django, this changes where outside researchers send their findings. Anyone who files reports on Django's behalf, or who tracks its security process, should use the email address from now on. Reports sent to HackerOne after this change are not covered by the notice, so the email route is the one Django points to.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: Django.