An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank cyberstan for reporting this issue.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-django | Nov 14, 2025 | Nov 5, 2025 |
| Debian | — | Upgrade python-django | Dec 31, 2025 | Dec 31, 2025 |
| Django | — | Upgrade Django to the latest version | Nov 10, 2025 | Nov 5, 2025 |
| Redhat_linux | — | Upgrade automation-controller-serverUpgrade python3-commonmarkUpgrade python3-wheel-wheelUpgrade python3-execnetUpgrade python3-pytestUpgrade python3.11-django-ansible-baseUpgrade python3.11-django-ansible-base+authenticationUpgrade automation-hubUpgrade ansible-dev-toolsUpgrade python3-onigurumacffi-debuginfoUpgrade automation-eda-controllerUpgrade python3-lazy-object-proxy-debuginfoUpgrade python3.11-django-ansible-base+rest_filtersUpgrade python3-wcmatchUpgrade python3.11-ansible-compatUpgrade python3.11-ruamel-yaml-clib-debugsourceUpgrade python3-pathableUpgrade python3-parsleyUpgrade python3-gnupgUpgrade python3-jsonschemaUpgrade python3.11-django-ansible-base+jwt_consumerUpgrade ansible-navigatorUpgrade python3-pluggyUpgrade python3-pygmentsUpgrade ansible-runnerUpgrade python3-blackUpgrade automation-eda-controller-worker-servicesUpgrade python3-ruamel-yamlUpgrade python3-setuptools-wheelUpgrade ansible-coreUpgrade automation-eda-controller-event-stream-servicesUpgrade python3.11-django-ansible-base+api_documentationUpgrade python3-termcolorUpgrade python3.11-django-ansible-base+channel_authUpgrade python3.11-execnetUpgrade python3.11-django-ansible-base+oauth2_providerUpgrade python3-openapi-spec-validatorUpgrade moleculeUpgrade python3.11-pytest-ansibleUpgrade python3.11-django-ansible-base+rbacUpgrade python3.11-django-ansible-base+resource_registryUpgrade python3-pyproject-apiUpgrade receptor-debugsourceUpgrade python3-sqlparseUpgrade python3-typing-extensionsUpgrade automation-controller-cliUpgrade python3.11-pytestUpgrade python3-markupsafe-debuginfoUpgrade python3-pbrUpgrade python3-djangoUpgrade python3-clickUpgrade python3-openapi-schema-validatorUpgrade python3.11-pytest-xdistUpgrade python3-pathspecUpgrade python3-ansible-runnerUpgrade ansible-signUpgrade python3-lockfileUpgrade python3-gunicornUpgrade ansible-dev-environmentUpgrade ansible-lintUpgrade python3.11-gunicornUpgrade python3.11-django-ansible-base+feature_flagsUpgrade python3-onigurumacffiUpgrade python3-enrichUpgrade python-markupsafe-debugsourceUpgrade receptorUpgrade automation-gateway-serverUpgrade python3-more-itertoolsUpgrade automation-controller-venv-towerUpgrade python3-asgirefUpgrade python3-platformdirsUpgrade python-rpds-py-debugsourceUpgrade ansible-creatorUpgrade python3-chardetUpgrade python3-iniconfigUpgrade python3-jsonschema-specificationsUpgrade python3-openapi-coreUpgrade python3.11-distlibUpgrade automation-controllerUpgrade automation-controller-uiUpgrade python-ruamel-yaml-clib-debugsourceUpgrade python3.11-ruamel-yaml-clib-debuginfoUpgrade bindepUpgrade yamllintUpgrade python3-tox-ansibleUpgrade python3-ansible-compatUpgrade python3.11-pluggyUpgrade python3-distlibUpgrade python3-pytest-sugarUpgrade python3-pytest-ansibleUpgrade python3.11-typing-extensionsUpgrade python3-virtualenvUpgrade automation-platform-uiUpgrade python3-filelockUpgrade python3-rfc3339-validatorUpgrade python3-werkzeugUpgrade python3.11-djangoUpgrade automation-gatewayUpgrade python3-pytest-xdistUpgrade python3.11-ruamel-yaml-clibUpgrade receptor-debuginfoUpgrade ansible-dev-tools+serverUpgrade python3.11-tox-ansibleUpgrade python3.11-django-ansible-base+redis_clientUpgrade python3-ruamel-yaml-clib-debuginfoUpgrade ansible-builderUpgrade python3-referencingUpgrade python3-lazy-object-proxyUpgrade receptorctlUpgrade python3-jsonschema-pathUpgrade python3-daemonUpgrade python3-click-help-colorsUpgrade python3-cachetoolsUpgrade automation-eda-controller-baseUpgrade python3-coloramaUpgrade python3.11-galaxy-ngUpgrade python3-mypy-extensionsUpgrade python-lazy-object-proxy-debugsourceUpgrade python3-subprocess-teeUpgrade python3-ruamel-yaml-clibUpgrade python3-rpds-pyUpgrade python3-bracexUpgrade python3.11-subprocess-teeUpgrade automation-eda-controller-base-servicesUpgrade python-onigurumacffi-debugsourceUpgrade python3-pytest-plusUpgrade python3.11-django-ansible-base+activitystreamUpgrade python3-isodateUpgrade python3.11-galaxy-importerUpgrade python3-markupsafeUpgrade python3-parseUpgrade python3-rpds-py-debuginfoUpgrade python3-richUpgrade automation-gateway-configUpgrade tox | Dec 12, 2025 | Nov 5, 2025 |
| Suse | — | Upgrade python3-django | Dec 5, 2025 | Dec 5, 2025 |
| Ubuntu | — | Upgrade python3-django (Ubuntu Pro)Upgrade python3-django | Nov 6, 2025 | Nov 5, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub