I've never really looked at Django's site before, picked 'community' on the upper right, and it says
> Report potential security issues in Django via private email to
> security@djangoproject.com, and not via Django's Trac instance or the
> django-developers mailing list
The community page (where all the mailing lists and contact addresses are listed) say:
>Report potential security issues in Django via private email to security@djangoproject.com, and not via Django's Trac instance or the django-developers mailing list