django-cors-headers
django-cors-headers is a Django application for handling the server headers required for Cross-Origin Resource Sharing (CORS).
Decision gist · record as of 2026-08-14
Yes. This is a mature, actively maintained, widely-deployed package with no known vulnerabilities, low install friction, and a permissive MIT license. It solves a common and necessary problem in modern web development. Install it if you need to serve cross-origin requests from browsers or other clients.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- CorsMiddleware must be placed high in the MIDDLEWARE list, before CommonMiddleware or other response-generating middleware, or CORS headers will not be added.
- Low friction installation as a pure Python wheel.
- Actively maintained with recent commits and a large contributor base; marked Production/Stable.
License · maintenance · safety
MIT (permissive) — MIT license permits commercial and private use with minimal restrictions, making it safe to adopt in any project type.
last release 2025-09-18 (330 days) · last repo commit 2026-08-13 · 5,592 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 21,723,504 downloads/mo, #992 on PyPI
Alternatives
Verify before relying
pip install django-cors-headers
# In settings.py
INSTALLED_APPS = [
"corsheaders",
...,
]
MIDDLEWARE = [
"corsheaders.middleware.CorsMiddleware",
"django.middleware.common.CommonMiddleware",
...,
]
CORS_ALLOWED_ORIGINS = [
"https://example.com",
"http://localhost:8080",
]- Whether the package handles all modern CORS preflight request scenarios (OPTIONS method, credential handling, custom headers).
- Performance impact when handling many concurrent cross-origin requests.
What it is and what it does
django-cors-headers is a Django middleware package that automatically adds the HTTP headers required by the CORS specification to your application's responses. This allows web browsers to make cross-origin requests (requests from one domain to another) to your Django application, which browsers normally block for security reasons. The package has been in active development since 2013 and is widely used in production Django applications.
You configure it by adding the middleware to your Django settings and specifying which origins are allowed to make requests—either as a list of specific domains, regex patterns for dynamic matching, or by allowing all origins. It handles the preflight OPTIONS requests that browsers send automatically and adds the appropriate Access-Control-Allow-* headers to responses. The package requires Django 4.2 to 6.0 and Python 3.9 or later, with no compiled dependencies beyond Django itself.
Use it for
- Enable a separate frontend application (React, Vue, etc.) running on a different domain to make API calls to your Django backend.
- Allow mobile apps or third-party web services to access your Django REST API endpoints across domain boundaries.
- Configure regex-based origin matching when you have many subdomains that need CORS access without listing each one individually.
- Restrict CORS headers to specific URL paths (e.g., only /api/*) while keeping other parts of your site protected.
- Handle browser preflight requests automatically without writing custom middleware code.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
This is a mature, actively maintained, widely-deployed package with no known vulnerabilities, low install friction, and a permissive MIT license. It solves a common and necessary problem in modern web development. Install it if you need to serve cross-origin requests from browsers or other clients.
Install
django-cors-headers on PyPI
Before you install
Low friction installation as a pure Python wheel. Actively maintained with recent commits and a large contributor base; marked Production/Stable. Depends only on asgiref and django, both standard Django ecosystem packages.
CorsMiddleware must be placed high in the MIDDLEWARE list, before CommonMiddleware or other response-generating middleware, or CORS headers will not be added.
License in practice
MIT license permits commercial and private use with minimal restrictions, making it safe to adopt in any project type.
Quickstart
pip install django-cors-headers
# In settings.py
INSTALLED_APPS = [
"corsheaders",
...,
]
MIDDLEWARE = [
"corsheaders.middleware.CorsMiddleware",
"django.middleware.common.CommonMiddleware",
...,
]
CORS_ALLOWED_ORIGINS = [
"https://example.com",
"http://localhost:8080",
]
Verify before relying
- Whether the package handles all modern CORS preflight request scenarios (OPTIONS method, credential handling, custom headers).
- Performance impact when handling many concurrent cross-origin requests.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesasgirefdjango |
| Maintenance | Actively maintained 330 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 21,723,504 / month, #992 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: Web EnvironmentFramework :: DjangoFramework :: Django :: 4.2Framework :: Django :: 5.0Framework :: Django :: 5.1Framework :: Django :: 5.2Framework :: Django :: 6.0Intended Audience :: DevelopersNatural Language :: EnglishOperating System :: OS IndependentProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPythonTyping :: Typed |
Evidence: django_cors_headers-4.9.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “django cors headers”
- django-cors-headersAdds Cross-Origin Resource Sharing (CORS) headers to Django…
- cherrypy-corsAdds Cross-Origin Resource Sharing (CORS) support to CherryPy…
- flask-corsFlask-CORS handles Cross-Origin Resource Sharing (CORS) headers in…
Give your agent the search over MCP, or paste the wish link into any chat.
More Dynamic Content packages
MarkupSafe provides a text object that escapes special characters so untrusted strings can be safely embedded in HTML and XML without injection attacks.
Jinja2 is a templating engine that renders dynamic content by combining templates with Python-like syntax and data, supporting template inheritance, macros, autoescaping, and sandboxed execution.
Soupsieve is a CSS selector library designed to work with Beautiful Soup 4 to select, match, and filter HTML and XML elements using modern CSS selectors from CSS level 1 through CSS level 4 specifications.
Install it if you use Beautiful Soup for HTML or XML parsing and want modern CSS selector support.
Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.
Flask is a lightweight WSGI web application framework for building web applications in Python, from simple single-page sites to complex multi-route applications.
Mako compiles Python-embedded templates into Python modules for fast rendering, supporting layout inheritance, custom functions, and direct Python expressions within template syntax.
See also aiohttp-cors · cherrypy-cors · django-permissions-policy · flask-cors · quart-cors · fastapi-cors · Sanic-Cors · aiohttp-middlewares · WebOb · django-request-logging