---
id: CVE-2024-26164
aliases:
  - GHSA-vmqv-47j8-gwv8
  - PYSEC-2026-1684
title: Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server
summary: Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: mssql-django
product: mssql-django
ecosystem: pip
affected:
  - mssql-django < 1.4.1
patched:
  - mssql-django 1.4.1
published: '2024-03-12'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-vmqv-47j8-gwv8'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-26164'
  - url: 'https://github.com/microsoft/mssql-django'
  - url: 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26164'
tags:
  - osv
  - pip
epss: 0.02106
epssPercentile: 0.80945
ingestedAt: '2026-07-08T18:25:53.349Z'
---

## Overview

Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability

## Affected packages

- `mssql-django < 1.4.1`

## Remediation

Upgrade to a patched release:

- `mssql-django 1.4.1`
