CVE-2024-53908Critical· 9.8▾ MidnightDjango SQL injection in HasKey(lhs, rhs) on Oracle
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.4%
An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via __ are unaffected.)
django >= 5.0.0, < 5.0.10django >= 5.1.0, < 5.1.4django >= 4.2.0, < 4.2.17django >= 5.1, < 5.1.4django >= 5.0, < 5.0.10django >= 4.2, < 4.2.17Upgrade to a patched release:
django 5.0.10django 5.1.4django 4.2.17django 5.1.4django 5.0.10django 4.2.17Connected by shared product, vendor, weakness, or advisory.
CVE-2026-5766Medium· 5.3Django has an Improper Handling of Length Parameter Inconsistency
CVE-2025-64460MediumDjango is vulnerable to DoS via XML serializer text extraction
CVE-2025-13372Medium· 4.3Django is vulnerable to SQL injection in column aliases
CVE-2025-64458High· 7.5Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2024-56374Medium· 5.8Django has a potential denial-of-service vulnerability in IPv6 validation
CVE-2025-26699Medium· 5.0Django vulnerable to Allocation of Resources Without Limits or Throttling