OSPulse

Is jinja2 healthy, maintained, and safe?

10/ 100
jinja2v3.1.6
Critical riskconfidence: Highview on pypi.org

No — Jinja2's health signals are critical and warrant replacing or forking.

vital-signs traceflatline

The verdict

Jinja2 earns a health score of 10/100, a critical risk rating, computed deterministically from live PyPI release history, and the OSV vulnerability database. No — Jinja2's health signals are critical and warrant replacing or forking.

Nothing has shipped since 5 March 2025 — over a year ago (509 days) — which points to a dormant project. Historically it released far more frequently, so the current silence reads as a genuine collapse in velocity rather than a natural gap. PyPI doesn't expose a reliable maintainer count, so bus-factor isn't scored here — treat maintenance depth as unknown rather than assumed.

OSV lists 20 known advisories for Jinja2, including 3 high. Review whether your version is in the affected range and whether a fixed release is available before depending on it. Each advisory is listed with its OSV/GHSA identifier below.

The safest reading is to replace, fork, or tightly pin Jinja2 and stop taking on new exposure to it. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own requirements.txt through the free health check, or have OSPulse monitor your whole dependency tree continuously.

Evidence trail — deterministic, auditable

Last release recency
509 days ago · dormant >1yr
-30
Release cadence
typical gap ~60d · now 509d — velocity collapse
-15
Maintainer bus factor
not available from PyPI — not penalised
Known vulnerabilities (OSV)
20 advisories · 3 high
-45
Package age
18.1 years · 52 releases

Known vulnerabilities (20)

  • GHSA-462w-v97r-4m45HIGHCVE-2019-10906PYSEC-2019-217

    Jinja2 sandbox escape via string formatting

  • GHSA-8r7q-cvjq-x353HIGHCVE-2014-1402PYSEC-2014-8

    Incorrect Privilege Assignment in Jinja2

  • GHSA-cpwx-vrp4-4pq7MODERATECVE-2025-27516PYSEC-2026-1471

    Jinja2 vulnerable to sandbox breakout through attr filter selecting format method

  • GHSA-fqh9-2qgg-h84hMODERATECVE-2014-0012PYSEC-2014-82

    Insecure Temporary File in Jinja2

  • GHSA-g3rq-g295-4j3mMODERATECVE-2020-28493PYSEC-2021-66SNYK-PYTHON-JINJA2-1012994

    Regular Expression Denial of Service (ReDoS) in Jinja2

  • GHSA-gmj6-6f8f-6699MODERATECVE-2024-56201PYSEC-2026-1472

    Jinja has a sandbox breakout through malicious filenames

  • GHSA-h5c8-rqwp-cp95MODERATECVE-2024-22195PYSEC-2026-1473

    Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

  • GHSA-h75v-3vvj-5mfjMODERATECVE-2024-34064PYSEC-2026-1474

    Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

  • GHSA-hj2j-77xm-mc5vHIGHCVE-2016-10745PYSEC-2019-220

    Jinja2 sandbox escape vulnerability

  • GHSA-q2x7-8rv6-6q7hMODERATECVE-2024-56326PYSEC-2026-1475

    Jinja has a sandbox breakout through indirect reference to format method

  • PYSEC-2014-8UNKNOWNCVE-2014-1402GHSA-8r7q-cvjq-x353

    The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file wit

  • PYSEC-2014-82UNKNOWNCVE-2014-0012GHSA-fqh9-2qgg-h84h

    FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this

  • PYSEC-2019-217UNKNOWNCVE-2019-10906GHSA-462w-v97r-4m45

    In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.

  • PYSEC-2019-220UNKNOWNCVE-2016-10745GHSA-hj2j-77xm-mc5v

    In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.

  • PYSEC-2021-66UNKNOWNCVE-2020-28493GHSA-g3rq-g295-4j3mSNYK-PYTHON-JINJA2-1012994

    This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the

  • PYSEC-2026-1471MEDIUMCVE-2025-27516GHSA-cpwx-vrp4-4pq7

    Jinja2 vulnerable to sandbox breakout through attr filter selecting format method

  • PYSEC-2026-1472LOWCVE-2024-56201GHSA-gmj6-6f8f-6699

    Jinja has a sandbox breakout through malicious filenames

  • PYSEC-2026-1473LOWCVE-2024-22195GHSA-h5c8-rqwp-cp95

    Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

  • PYSEC-2026-1474LOWCVE-2024-34064GHSA-h75v-3vvj-5mfj

    Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

  • PYSEC-2026-1475LOWCVE-2024-56326GHSA-q2x7-8rv6-6q7h

    Jinja has a sandbox breakout through indirect reference to format method

Key facts

Latest version
v3.1.6
Last release
5 March 2025 (509 days ago)
Total releases
52
First release
9 June 2008
Package age
18.1 years
Maintainers
not exposed by PyPI
Known advisories
20
Confidence
High

Frequently asked

Is Jinja2 still maintained?

Partly — the most recent release was 5 March 2025 (509 days ago), so maintenance has slowed but not fully stopped.

Does Jinja2 have known security vulnerabilities?

Yes — OSV lists 20 advisories for Jinja2. See the advisory list on this page for the OSV/GHSA identifiers.

Is Jinja2 safe to use?

No — Jinja2's health signals are critical and warrant replacing or forking. OSPulse rates it 10/100 (critical risk) based on release recency, cadence and known vulnerabilities.

Other PyPI packages we've checked

Browse all checked packages →

jinja2 is one package. What about the other hundreds in your tree?

Paste your own requirements.txt into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.

Data from the PyPI registry & OSV.dev · snapshot generated 2026-07-27 · scores are deterministic and recomputed on each refresh.