`FilteredRelation` is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the `**kwargs` passed to `QuerySet.annotate()` or `QuerySet.alias()` on PostgreSQL.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Stackered for reporting this issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6117-1 | python-django security update |
Debian DSA |
DSA-6136-1 | python-django security update |
Github GHSA |
GHSA-rqw2-ghq9-44m7 | Django is vulnerable to SQL injection in column aliases |
Ubuntu USN |
USN-7903-1 | Django vulnerabilities |
Wed, 17 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 12 Dec 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* |
Wed, 03 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Djangoproject
Djangoproject django |
|
| Vendors & Products |
Djangoproject
Djangoproject django |
Tue, 02 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. `FilteredRelation` is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the `**kwargs` passed to `QuerySet.annotate()` or `QuerySet.alias()` on PostgreSQL. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Stackered for reporting this issue. | |
| Title | Potential SQL injection in FilteredRelation column aliases on PostgreSQL | |
| Weaknesses | CWE-89 | |
| References |
|
Status: PUBLISHED
Assigner: DSF
Published:
Updated: 2025-12-02T15:43:47.127Z
Reserved: 2025-11-18T18:34:58.688Z
Link: CVE-2025-13372
Updated: 2025-12-02T15:43:42.505Z
Status : Analyzed
Published: 2025-12-02T16:15:53.907
Modified: 2025-12-12T12:57:23.833
Link: CVE-2025-13372
OpenCVE Enrichment
Updated: 2025-12-03T12:10:04Z
Debian DSA
Github GHSA
Ubuntu USN