Is jinja2 healthy, maintained, and safe?
No — Jinja2's health signals are critical and warrant replacing or forking.
The verdict
Jinja2 earns a health score of 10/100, a critical risk rating, computed deterministically from live PyPI release history, and the OSV vulnerability database. No — Jinja2's health signals are critical and warrant replacing or forking.
Nothing has shipped since 5 March 2025 — over a year ago (509 days) — which points to a dormant project. Historically it released far more frequently, so the current silence reads as a genuine collapse in velocity rather than a natural gap. PyPI doesn't expose a reliable maintainer count, so bus-factor isn't scored here — treat maintenance depth as unknown rather than assumed.
OSV lists 20 known advisories for Jinja2, including 3 high. Review whether your version is in the affected range and whether a fixed release is available before depending on it. Each advisory is listed with its OSV/GHSA identifier below.
The safest reading is to replace, fork, or tightly pin Jinja2 and stop taking on new exposure to it. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own requirements.txt through the free health check, or have OSPulse monitor your whole dependency tree continuously.
Evidence trail — deterministic, auditable
Known vulnerabilities (20)
Jinja2 sandbox escape via string formatting
Incorrect Privilege Assignment in Jinja2
Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
Insecure Temporary File in Jinja2
Regular Expression Denial of Service (ReDoS) in Jinja2
Jinja has a sandbox breakout through malicious filenames
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja2 sandbox escape vulnerability
Jinja has a sandbox breakout through indirect reference to format method
The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file wit
FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the
Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
Jinja has a sandbox breakout through malicious filenames
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja has a sandbox breakout through indirect reference to format method
Key facts
- Latest version
- v3.1.6
- Last release
- 5 March 2025 (509 days ago)
- Total releases
- 52
- First release
- 9 June 2008
- Package age
- 18.1 years
- Maintainers
- not exposed by PyPI
- Known advisories
- 20
- Confidence
- High
Frequently asked
Is Jinja2 still maintained?
Partly — the most recent release was 5 March 2025 (509 days ago), so maintenance has slowed but not fully stopped.
Does Jinja2 have known security vulnerabilities?
Yes — OSV lists 20 advisories for Jinja2. See the advisory list on this page for the OSV/GHSA identifiers.
Is Jinja2 safe to use?
No — Jinja2's health signals are critical and warrant replacing or forking. OSPulse rates it 10/100 (critical risk) based on release recency, cadence and known vulnerabilities.
Other PyPI packages we've checked
jinja2 is one package. What about the other hundreds in your tree?
Paste your own requirements.txt into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.
Data from the PyPI registry & OSV.dev · snapshot generated 2026-07-27 · scores are deterministic and recomputed on each refresh.
