CVE-2025-57833High· 7.1▾ MidnightPoC availableDjango is subject to SQL injection through its column aliases
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 39.1 · likelihood 3.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
16%
5 GitHub repos (last check)
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().
django < 4.2.24django >= 5.0a1, < 5.1.12django >= 5.2a1, < 5.2.6Upgrade to a patched release:
django 4.2.24django 5.1.12django 5.2.6Connected by shared product, vendor, weakness, or advisory.
CVE-2025-64458High· 7.5Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2025-32873Medium· 5.3Django has a denial-of-service possibility in strip_tags()
CVE-2026-33033Medium· 6.5Django has potential DoS via MultiPartParser through crafted multipart uploads
CVE-2026-1312Medium· 5.4An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, w…
CVE-2026-1207Medium· 5.4An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupport…
CVE-2026-5766Medium· 5.3Django has an Improper Handling of Length Parameter Inconsistency