Today the Django team issued 1.9.2 as part of our security process. This releases address a security issue, and we encourage all users to upgrade as soon as possible.
The Django 1.8.9 release fixes several bugs in 1.8.8 but no security issues as the issue fixed in 1.9.2 doesn't affect older versions.
Details are available on the Django project weblog:
https://www.djangoproject.com/weblog/2016/feb/01/releases-192-and-189/As a reminder, we ask that potential security issues be reported via private email to
secu...@djangoproject.com and not via Django's Trac instance or the django-developers list. Please see
https://www.djangoproject.com/security for further information.