django-allow-cidr
A Django Middleware to enable use of CIDR IP ranges in ALLOWED_HOSTS.
Decision gist · record as of 2026-08-14
Yes, if you need to validate Host headers against CIDR ranges. The middleware is straightforward, has no known vulnerabilities, carries a permissive license, and integrates cleanly with Django's standard security model. The aging maintenance status is not a blocker—the package is stable, recently updated for current Django and Python versions, and solves a specific problem without heavy dependencies.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low friction installation with a single pure-Python dependency on Django.
- The package is aging (last release 493 days ago) but remains actively maintained on the repository, with recent CI updates for Django 5.2 and Python 3.13 support.
License · maintenance · safety
Apache Software License 2.0 (permissive) — Licensed under Apache Software License 2.0, a permissive license that allows commercial use, modification, and distribution with minimal restrictions.
last release 2025-04-08 (493 days) · last repo commit 2025-09-25 · 111 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 965,054 downloads/mo, #4,624 on PyPI
Alternatives
Verify before relying
pip install django-allow-cidr
# In settings.py
MIDDLEWARE = (
'allow_cidr.middleware.AllowCIDRMiddleware',
...
)
ALLOWED_CIDR_NETS = ['192.168.1.0/24']- Whether the middleware correctly handles edge cases like IPv6 addresses with zone identifiers or non-standard CIDR notation
- Performance impact when ALLOWED_CIDR_NETS contains a large number of networks
What it is and what it does
django-allow-cidr is a Django middleware that augments the standard ALLOWED_HOSTS validation by adding support for CIDR network ranges. Instead of listing individual IP addresses or hostnames, you define subnets using standard CIDR notation (e.g., 192.168.1.0/24) in an ALLOWED_CIDR_NETS setting, and the middleware validates incoming Host headers against both the traditional ALLOWED_HOSTS and your CIDR ranges. When ALLOWED_CIDR_NETS is configured, the middleware takes over Host header validation entirely, replacing ALLOWED_HOSTS with ['*'] internally to prevent Django's default validation from interfering.
The package uses Python's built-in ipaddress library for network validation, supports both IPv4 and IPv6, and works alongside normal ALLOWED_HOSTS entries. It is designed as a drop-in middleware that requires minimal configuration—just add it to the top of your MIDDLEWARE list and define your CIDR ranges.
Use it for
- Whitelist entire office or data-center subnets without listing every individual IP address
- Allow requests from cloud provider IP ranges or load-balancer subnets in production environments
- Restrict API access to specific network segments in multi-tenant or internal-only deployments
- Simplify Host header validation when you control the network topology but not individual client IPs
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need to validate Host headers against CIDR ranges.
The middleware is straightforward, has no known vulnerabilities, carries a permissive license, and integrates cleanly with Django's standard security model. The aging maintenance status is not a blocker—the package is stable, recently updated for current Django and Python versions, and solves a specific problem without heavy dependencies.
Install
django-allow-cidr on PyPI
Before you install
Low friction installation with a single pure-Python dependency on Django. The package is aging (last release 493 days ago) but remains actively maintained on the repository, with recent CI updates for Django 5.2 and Python 3.13 support.
License in practice
Licensed under Apache Software License 2.0, a permissive license that allows commercial use, modification, and distribution with minimal restrictions.
Quickstart
pip install django-allow-cidr
# In settings.py
MIDDLEWARE = (
'allow_cidr.middleware.AllowCIDRMiddleware',
...
)
ALLOWED_CIDR_NETS = ['192.168.1.0/24']
Verify before relying
- Whether the middleware correctly handles edge cases like IPv6 addresses with zone identifiers or non-standard CIDR notation
- Performance impact when ALLOWED_CIDR_NETS contains a large number of networks
Package facts
| License | Apache Software License 2.0 permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packageDjango |
| Maintenance | Aging 493 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 965,054 / month, #4,624 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaFramework :: DjangoFramework :: Django :: 4.2Framework :: Django :: 5.1Framework :: Django :: 5.2Intended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseNatural Language :: EnglishProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9 |
Evidence: django_allow_cidr-0.8.0-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “django cidr ip ranges”
- django-allow-cidrA Django middleware that extends ALLOWED_HOSTS validation to support…
- iptoolsProvides utilities for parsing, validating, and manipulating IPv4 and…
- netaddrRepresents and manipulates IPv4, IPv6, MAC addresses and related…
Give your agent the search over MCP, or paste the wish link into any chat.
More WWW/HTTP packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.
HTTPX is a fully featured HTTP client library for Python that provides both sync and async APIs, with support for HTTP/1.1 and HTTP/2, plus an integrated command-line client.
Install it if you are building new projects or modernizing existing ones that rely on HTTP.
A minimal low-level HTTP client library that sends HTTP requests with thread-safe and task-safe connection pooling, supporting HTTP/1.1, HTTP/2, proxies, and both sync and async interfaces.
aiohttp is an async HTTP client and server framework built on asyncio, supporting both WebSockets and middleware-based routing for building concurrent web applications.
Install it if you need async HTTP client or server capabilities in asyncio-based applications.
See also django-ebhealthcheck · django-netfields · netaddr · iptools · django-xff · ipaddr · django-localflavor · cidr-trie · ipaddress · django-axes