An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank cyberstan for reporting this issue.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-django | Nov 14, 2025 | Nov 5, 2025 |
| Debian | — | Upgrade python-django | Dec 31, 2025 | Dec 31, 2025 |
| Django | — | Upgrade Django to the latest version | Nov 10, 2025 | Nov 5, 2025 |
| Redhat_linux | — | Upgrade python3-tox-ansibleUpgrade python3-pytest-sugarUpgrade python3-iniconfigUpgrade python3.11-tox-ansibleUpgrade ansible-dev-tools+serverUpgrade python3.11-django-ansible-base+redis_clientUpgrade python3-pytest-xdistUpgrade python3.11-distlibUpgrade python3-ansible-compatUpgrade python3-distlibUpgrade python3-referencingUpgrade receptorctlUpgrade python3.11-pluggyUpgrade python3-filelockUpgrade yamllintUpgrade python3.11-galaxy-ngUpgrade python3.11-ruamel-yaml-clibUpgrade python3-cachetoolsUpgrade python3.11-subprocess-teeUpgrade python3-mypy-extensionsUpgrade python3-rpds-py-debuginfoUpgrade python3-click-help-colorsUpgrade python3.11-galaxy-importerUpgrade python3-ruamel-yaml-clib-debuginfoUpgrade python3-virtualenvUpgrade automation-eda-controller-base-servicesUpgrade python3.11-django-ansible-base+activitystreamUpgrade python3-jsonschema-pathUpgrade python3-daemonUpgrade python3-lazy-object-proxyUpgrade python3-coloramaUpgrade automation-eda-controller-baseUpgrade python3-bracexUpgrade python3-subprocess-teeUpgrade python3-rpds-pyUpgrade automation-controllerUpgrade python3-pytest-plusUpgrade python3.11-djangoUpgrade python3-rfc3339-validatorUpgrade receptor-debuginfoUpgrade python3.11-typing-extensionsUpgrade python3-richUpgrade python-ruamel-yaml-clib-debugsourceUpgrade automation-gateway-configUpgrade python3.11-ruamel-yaml-clib-debuginfoUpgrade python3-parseUpgrade python3-jsonschema-specificationsUpgrade bindepUpgrade automation-controller-uiUpgrade ansible-builderUpgrade python3-markupsafeUpgrade python3-isodateUpgrade toxUpgrade python3-openapi-coreUpgrade python3-pytest-ansibleUpgrade python3-werkzeugUpgrade automation-platform-uiUpgrade python3-ruamel-yaml-clibUpgrade python-lazy-object-proxy-debugsourceUpgrade automation-gatewayUpgrade python-onigurumacffi-debugsourceUpgrade python3-openapi-spec-validatorUpgrade python3-enrichUpgrade python3.11-django-ansible-base+api_documentationUpgrade automation-eda-controller-event-stream-servicesUpgrade automation-eda-controller-worker-servicesUpgrade python3-typing-extensionsUpgrade python3-termcolorUpgrade python3-pathspecUpgrade python3-openapi-schema-validatorUpgrade python3-clickUpgrade python3.11-pytest-xdistUpgrade python3-ansible-runnerUpgrade python3.11-django-ansible-base+resource_registryUpgrade receptorUpgrade python3-onigurumacffiUpgrade python3.11-gunicornUpgrade python3.11-django-ansible-base+feature_flagsUpgrade python-markupsafe-debugsourceUpgrade ansible-lintUpgrade ansible-dev-environmentUpgrade python-rpds-py-debugsourceUpgrade python3-asgirefUpgrade ansible-runnerUpgrade python3.11-django-ansible-base+oauth2_providerUpgrade python3-lockfileUpgrade python3-markupsafe-debuginfoUpgrade python3-sqlparseUpgrade python3-execnetUpgrade python3.11-django-ansible-base+rbacUpgrade python3-gnupgUpgrade python3-ruamel-yamlUpgrade python3-setuptools-wheelUpgrade python3.11-pytestUpgrade ansible-dev-toolsUpgrade python3-gunicornUpgrade python3-djangoUpgrade python3.11-django-ansible-base+jwt_consumerUpgrade python3.11-ansible-compatUpgrade automation-eda-controllerUpgrade automation-hubUpgrade automation-controller-cliUpgrade moleculeUpgrade python3-onigurumacffi-debuginfoUpgrade python3-pbrUpgrade python3-blackUpgrade python3.11-ruamel-yaml-clib-debugsourceUpgrade python3-parsleyUpgrade python3-jsonschemaUpgrade ansible-coreUpgrade python3-pygmentsUpgrade python3-wcmatchUpgrade automation-controller-serverUpgrade ansible-creatorUpgrade python3-chardetUpgrade receptor-debugsourceUpgrade python3-lazy-object-proxy-debuginfoUpgrade python3-pluggyUpgrade python3.11-django-ansible-base+rest_filtersUpgrade python3-commonmarkUpgrade python3-pathableUpgrade python3-platformdirsUpgrade automation-gateway-serverUpgrade python3-pyproject-apiUpgrade python3.11-pytest-ansibleUpgrade python3-more-itertoolsUpgrade python3-pytestUpgrade ansible-signUpgrade python3-wheel-wheelUpgrade automation-controller-venv-towerUpgrade ansible-navigatorUpgrade python3.11-django-ansible-base+channel_authUpgrade python3.11-execnetUpgrade python3.11-django-ansible-base+authenticationUpgrade python3.11-django-ansible-base | Dec 12, 2025 | Nov 5, 2025 |
| Suse | — | Upgrade python3-django | Dec 5, 2025 | Dec 5, 2025 |
| Ubuntu | — | Upgrade python3-django (Ubuntu Pro)Upgrade python3-django | Nov 6, 2025 | Nov 5, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub