The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank cyberstan for reporting this issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4425-1 | python-django security update |
Debian DSA |
DSA-6117-1 | python-django security update |
Debian DSA |
DSA-6136-1 | python-django security update |
Github GHSA |
GHSA-frmv-pr5f-9mcr | Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects. |
Ubuntu USN |
USN-7859-1 | Django vulnerabilities |
Tue, 11 Nov 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 10 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* |
Sat, 08 Nov 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 06 Nov 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Djangoproject
Djangoproject django |
|
| Vendors & Products |
Djangoproject
Djangoproject django |
Wed, 05 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 05 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank cyberstan for reporting this issue. | |
| Title | Potential SQL injection via _connector keyword argument in QuerySet and Q objects | |
| Weaknesses | CWE-89 | |
| References |
|
Status: PUBLISHED
Assigner: DSF
Published:
Updated: 2026-02-26T17:47:16.519Z
Reserved: 2025-11-04T14:35:57.527Z
Link: CVE-2025-64459
Updated: 2025-11-08T12:49:45.129Z
Status : Analyzed
Published: 2025-11-05T15:15:41.080
Modified: 2025-11-10T18:25:59.883
Link: CVE-2025-64459
OpenCVE Enrichment
Updated: 2025-11-06T10:07:02Z
Debian DLA
Debian DSA
Github GHSA
Ubuntu USN