NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1882 most downloaded on PyPI
Django ASGI (HTTP/WebSocket) server
Last release 2 months ago
21 Jul 2026
Release timing varies
gaps range from 2 weeks to 1.4 years
Nearly every release is documented
notes for 57 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
64 releases · first in 2016
Added --websocket-max-message-size and --websocket-max-frame-size CLI flags to the runserver management command for use in development.
--websocket-max-message-size and --websocket-max-frame-size CLI
flags to the runserver management command for use in development.This allowed an unauthenticated client to exhaust server memory by sending a very large WebSocket messages/frames (CVE-2026-44545).
Fixed a denial of service vulnerability via unbounded WebSocket message sizes. Daphne previously passed no message or frame size limits to autobahn, whose defaults are unbounded. This allowed an unauthenticated client to exhaust server memory by sending a very large WebSocket messages/frames (CVE-2026-44545).
Both limits now default to 1 MiB and can be configured via the new
--websocket-max-message-size and --websocket-max-frame-size CLI
flags (or the matching Server constructor arguments). Pass 0 to
restore the previous unlimited behaviour.
Thanks to ParkHyunWoo for the report.
Fixed a header injection vulnerability on the WebSocket upgrade path (CVE-2026-44546).
Header values containing \x0b, \x0c, \x1c, \x1d, \x1e,
or \x85 were parsed as a single header by Twisted but split into
multiple headers by autobahn during the WebSocket handshake. An attacker
could exploit this parser differential to smuggle additional headers
(e.g. authentication tokens, X-Forwarded-For, Origin,
Daphne-Root-Path) into the ASGI scope passed to the application.
Daphne now rejects requests carrying these bytes in any header value with a 400 Bad Request response, as required by RFC 9110 §5.5.
Thanks to Rene Henningsen for the report.
One column per quarter.
Fixed a packaging error in 4.2.0.
Fixed a packaging error in 4.2.0.
Removed --nostatic and --insecure args to runserver command when staticfiles app is not installed.
Daphne 4.2 is a maintenance release in the 4.x series.
Daphne 4.2 is a maintenance release in the 4.x series.
Added support for Python 3.13.
Dropped support for EOL Python 3.8.
Updated pyupgrade configuration to target Python 3.9.
Added a load_asgi_app hook to CLI class, useful for compiled or frozen
applications.
Allowed assigning a port in the DaphneProcess test helper, useful for live server test cases, such as that provided by Channels.
Added --nostatic and --insecure args to runserver command to match Django's built-in command.
Moved metadata to use pyproject.toml.
Updated sdist file to include tests and changelog.
Removed unused pytest-runner.
Fixed a setuptools configuration error in 4.1.1.
Fixed a twisted.plugin packaging error in 4.1.0.
Fixed a twisted.plugin packaging error in 4.1.0.
Thanks to sdc50.
Dropped support for EOL Python 3.7.
Added support for Python 3.12.
Dropped support for EOL Python 3.7.
Handled root path for websocket scopes.
Validate HTTP header names as per RFC 9110.
Previously a range of Twisted versions have been supported. Recent Twisted releases (22.2, 22.4) have issued security fixes, so those are now the mini…
Major versioning targeting use with Channels 4.0 and beyond. Except where noted should remain usable with Channels v3 projects, but updating Channels to the latest version is recommended.
Added a runserver command to run an ASGI Django development server.
Added "daphne" to the INSTALLED_APPS setting, before
"django.contrib.staticfiles" to enable:
INSTALLED_APPS = [ "daphne", ... ]
This replaces the Channels implementation of runserver, which is removed
in Channels 4.0.
Made the DaphneProcess tests helper class compatible with the spawn
process start method, which is used on macOS and Windows.
Note that requires Channels v4 if using with ChannelsLiveServerTestCase.
Dropped support for Python 3.6.
Updated dependencies to the latest versions.
Previously a range of Twisted versions have been supported. Recent Twisted releases (22.2, 22.4) have issued security fixes, so those are now the minimum supported version. Given the stability of Twisted, supporting a range of versions does not represent a good use of maintainer time. Going forward the latest Twisted version will be required.
Set daphne as default Server header.
This can be configured with the --server-name CLI argument.
Added the new --no-server-name CLI argument to disable the Server
header, which is equivalent to ``--server-name=` (an empty name).
Added --log-fmt CLI argument.
Added support for ASGI_THREADS environment variable, setting the maximum
number of workers used by a SyncToAsync thread-pool executor.
Set e.g. ASGI_THREADS=4 daphne ... when running to limit the number of
workers.
Removed deprecated --ws_protocols CLI option.
Nothing published for this version
Fixed a bug where send passed to applications wasn't a true async function but a lambda wrapper, preventing it from being used with asgiref.sync.async
send passed to applications wasn't a true async
function but a lambda wrapper, preventing it from being used with
asgiref.sync.async_to_sync().Fixed a bug where asyncio.CancelledError was not correctly handled on Python 3.8+, resulting in incorrect protocol application cleanup.
asyncio.CancelledError was not correctly handled on
Python 3.8+, resulting in incorrect protocol application cleanup.Updates internals to use ASGI v3 throughout. asgiref.compatibility is used for older applications.
Updates internals to use ASGI v3 throughout. asgiref.compatibility is
used for older applications.
Consequently, the --asgi-protocol command-line option is removed.
HTTP request bodies are now read, and passed to the application, in chunks.
Added support for Python 3.9.
Dropped support for Python 3.5.
Fixes compatability for twisted when running Python 3.8+ on Windows, by setting asyncio.WindowsSelectorEventLoopPolicy as the event loop policy in thi
Fixes compatability for twisted when running Python 3.8+ on Windows, by
setting asyncio.WindowsSelectorEventLoopPolicy as the event loop policy
in this case.
The internal daphne.testing.TestApplication now requires an addition
lock argument to __init__(). This is expected to be an instance of
multiprocessing.Lock.
Avoids Twisted using the default event loop, for compatibility with Django 3.0's async_unsafe() decorator in threaded contexts, such as using the auto
async_unsafe() decorator in threaded contexts, such as using the
auto-reloader.Adds CI testing against and support for Python 3.8.
Adds CI testing against and support for Python 3.8.
Adds support for raw_path in ASGI scope.
Ensures an error response is sent to the client if the application sends malformed headers.
Resolves an asyncio + multiprocessing problem when testing that would cause the test suite to fail/hang on macOS.
Requires installing Twisted's TLS extras, via install_requires.
Adds missing LICENSE to distribution.
* Added support for ASGI v3.
WebSocket handshakes are now affected by the websocket connect timeout, so you can limit them from the command line.
WebSocket handshakes are now affected by the websocket connect timeout, so you can limit them from the command line.
Server name can now be set using --server-name
No longer listens on port 8000 when a file descriptor is provided with --fd
No longer listens on port 8000 when a file descriptor is provided with --fd
Fixed a memory leak with WebSockets
Enforce that response headers are only bytestrings, rather than allowing unicode strings and coercing them into bytes.
Enforce that response headers are only bytestrings, rather than allowing unicode strings and coercing them into bytes.
New command-line options to set proxy header names: --proxy-headers-host and --proxy-headers-port.
X-Forwarded-Proto support is now present and enabled if you turn on the --proxy-headers flag
X-Forwarded-Proto support is now present and enabled if you turn on the --proxy-headers flag
ASGI applications are no longer instantiated in a thread (the ASGI spec was finalised to say all constructors must be non-blocking on the main thread)
Python 3.7 compatability is flagged and ensured by using Twisted 18.7 and above as a dependency.
Python 3.7 compatability is flagged and ensured by using Twisted 18.7 and above as a dependency.
The send() awaitable in applications no longer blocks if the connection is closed.
Fixed a race condition where applications would be cleaned up before they had even started.
HTTP timeouts have been removed by default, as they were only needed with ASGI/Channels 1. You can re-enable them with the --http-timeout argument to
HTTP timeouts have been removed by default, as they were only needed with ASGI/Channels 1. You can re-enable them with the --http-timeout argument to Daphne.
Occasional errors on application timeout for non-fully-opened sockets and for trying to read closed requests under high load are fixed.
X-Forwarded-For headers are now correctly decoded in all environments and no longer have unicode matching issues.
Fixed spurious errors caused by websockets disconnecting before their application was instantiated.
Fixed spurious errors caused by websockets disconnecting before their application was instantiated.
Stronger checking for type-safety of headers as bytestrings
ASGI application constructors are now run in a threadpool as they might contain blocking synchronous code.
Removed subprotocol support from server, as it never really worked. Subprotocols can instead be negotiated by ASGI applications now.
Removed subprotocol support from server, as it never really worked. Subprotocols can instead be negotiated by ASGI applications now.
Non-ASCII query strings now raise a 400 Bad Request error rather than silently breaking the logger
Ping timeouts no longer reset on outgoing data, only incoming data
Ping timeouts no longer reset on outgoing data, only incoming data
No more errors when connections close prematurely
Unix socket listening no longer errors during startup (introduced in 2.0.2)
Unix socket listening no longer errors during startup (introduced in 2.0.2)
ASGI Applications are now not immediately killed on disconnection but instead given --application-close-timeout seconds to exit (defaults to 10)
WebSockets are no longer closed after the duration of http_timeout
Updated logging to correctly route exceptions through the main Daphne logger
Major rewrite to the new async-based ASGI specification and to support Channels 2. Not backwards compatible.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Ability to set the websocket connection timeout
Ability to set the websocket connection timeout
Server no longer reveals the exact Autobahn version number for security
A few unicode fixes for Python 2/3 compatability
Stopped logging messages to already-closed connections as ERROR
The new process-specific channel support is now implemented, resulting in significantly less traffic to your channel backend.
The new process-specific channel support is now implemented, resulting in significantly less traffic to your channel backend.
Native twisted blocking support for channel layers that support it is now used. While it is a lot more efficient, it is also sometimes slightly more latent; you can disable it using --force-sync.
Native SSL termination is now correctly reflected in the ASGI-HTTP scheme
key.
accept: False is now a valid way to deny a connection, as well as close: True.
HTTP version is now correctly sent as one of "1.0", "1.1" or "2".
More command line options for websocket timeouts
HTTP/2 termination is now supported natively. The Twisted dependency has been increased to at least 17.1 as a result; for more information about setti
HTTP/2 termination is now supported natively. The Twisted dependency has been increased to at least 17.1 as a result; for more information about setting up HTTP/2, see the README.
X-Forwarded-For decoding support understands IPv6 addresses, and picks the most remote (leftmost) entry if there are multiple relay hosts.
Fixed an error where disconnect messages would still try and get sent even
if the client never finished a request.
IPv6 addresses are correctly accepted as bind targets on the command line
IPv6 addresses are correctly accepted as bind targets on the command line
Twisted 17.1 compatability fixes for WebSocket receiving/keepalive and proxy header detection.
The DeprecationError caused by not passing endpoints into a Server class directly is now a warning instead.
The "null" WebSocket origin (including file:// and no value) is now accepted by Daphne and passed onto the application to accept/deny.
Listening on file descriptors works properly again.
The DeprecationError caused by not passing endpoints into a Server class directly is now a warning instead.
Endpoint unicode strings now work correctly on Python 2 and Python 3
BREAKING CHANGE: Daphne now requires acceptance of WebSocket connections before it finishes the socket handshake and relays incoming packets. You must…
BREAKING CHANGE: Daphne now requires acceptance of WebSocket connections before it finishes the socket handshake and relays incoming packets. You must upgrade to at least Channels 1.0.0 as well; see http://channels.readthedocs.io/en/latest/releases/1.0.0.html for more.
http.disconnect now has a path key
WebSockets can now be closed with a specific code
X-Forwarded-For header support; defaults to X-Forwarded-For, override with --proxy-headers on the commandline.
Twisted endpoint description string support with -e on the command line
(allowing for SNI/ACME support, among other things)
Logging/error verbosity fixes and access log flushes properly
Connections now force-close themselves after pings fail for a certain timeframe, controllable via the new --ping-timeout option.
Connections now force-close themselves after pings fail for a certain timeframe, controllable via the new --ping-timeout option.
Badly-formatted websocket response messages now log to console in all situations
Compatability with Twisted 16.3 and up
File descriptors can now be passed on the commandline for process managers that pass sockets along like this.
File descriptors can now be passed on the commandline for process managers that pass sockets along like this.
websocket.disconnect messages now come with a "code" attribute matching the WebSocket spec.
A memory leak in request logging has been fixed.
Marked as incompatible with twisted 16.3 and above until we work out why it stops incoming websocket messages working
Consumption of websocket.receive is also now required.
Consumption of websocket.connect is now required (channels 0.16 enforces this); getting backpressure on it now results in the socket being force close
Bad WebSocket handshakes now return 400 and an error messages rather than 500 with no content.
Query strings are now sent as bytestrings and the application is responsible for decoding. Ensure you're running Channels 0.15 or higher.
Plus signs in query string are now handled by Daphne, not Django-by-mistake. Ensure you're running Channels 0.14.3 or higher.
Plus signs in query string are now handled by Daphne, not Django-by-mistake. Ensure you're running Channels 0.14.3 or higher.
New --root-path and DAPHNE_ROOT_PATH options for setting root path.
Fixed bug where a non-ASCII byte in URL paths would crash the HTTP parser without a response; now returns 400, and hardening in place to catch most ot
Fixed bug where a non-ASCII byte in URL paths would crash the HTTP parser without a response; now returns 400, and hardening in place to catch most other errors and return a 500.
WebSocket header format now matches HTTP header format and the ASGI spec. No update needed to channels library, but user code may need updating.
Backpressure on http.request now causes incoming requests to drop with 503. Websockets will drop connection/disconnection messages/received frames if
Don't decode + as a space in URLs
Correctly encode all path params for WebSockets
Fix bugs with WebSocket path parsing under Python 2
HTTP paths and query strings are now pre-decoded before going to ASGI
Error on badly formatted websocket reply messages
Access logging in NCSAish format now printed to stdout, configurable to another file using --access-log=filename
WebSockets now close after they've been open for longer than the channel layer group expiry (86400 seconds by default for most layers).
WebSockets now close after they've been open for longer than the channel layer group expiry (86400 seconds by default for most layers).
Binding to UNIX sockets is now possible (use the -u argument)
WebSockets now send keepalive pings if they've had no data for a certain amount of time (20 seconds by default, set with --ping-interval)
Multiple cookies are now set correctly
Multiple cookies are now set correctly
Follows new ASGI single-response-channel spec for !
Follows new ASGI header encoding spec for HTTP
WebSocket query strings are correctly encoded
HTTP requests now time out after a configurable amount of time and return 503 (default is 2 minutes)
Your coding agent can read these notes before it upgrades. Set up the MCP server →