PT-2025-35820 · Django +3 · Django +3
Eyal Gabay
+1
·
Published
2025-09-03
·
Updated
2025-09-06
·
CVE-2025-57833
7.1
High
Base vector | Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N |
**Name of the Vulnerable Software and Affected Versions:**
Django versions prior to 4.2.24
Django versions prior to 5.1.12
Django versions prior to 5.2.6
**Description:**
An issue has been discovered in Django’s FilteredRelation feature, allowing for SQL injection in column aliases when using a crafted dictionary with dictionary expansion as the `kwargs` passed to `QuerySet.annotate()` or `QuerySet.alias()`. This vulnerability could allow attackers to manipulate queries and potentially access sensitive data. Approximately 8.4 million services are estimated to be affected yearly.
**Recommendations:**
Django versions prior to 4.2.24: Upgrade to version 4.2.24 or later.
Django versions prior to 5.1.12: Upgrade to version 5.1.12 or later.
Django versions prior to 5.2.6: Upgrade to version 5.2.6 or later.
Fix
RCE
SQL injection
Weakness Enumeration
Related Identifiers
Affected Products
References · 41
- https://security-tracker.debian.org/tracker/source-package/python-django · Vendor Advisory
- https://ubuntu.com/security/CVE-2025-57833 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-57833 · Security Note
- https://security-tracker.debian.org/tracker/CVE-2025-57833 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-57833 · Security Note
- https://ubuntu.com/security/notices/USN-7736-1 · Vendor Advisory
- https://docs.djangoproject.com/en/dev/releases/security · Note
- https://twitter.com/NullSecurityX/status/1963876825148354707 · Twitter Post
- https://groups.google.com/g/django-announce · Note
- https://twitter.com/ZeroPathLabs/status/1963374555201773683 · Twitter Post
- https://twitter.com/wvipersg/status/1963576047443587073 · Twitter Post
- https://twitter.com/f1tym1/status/1963578928829747422 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1n9vszk/top_10_trending_cves_06092025 · Reddit Post
- https://t.me/CVEtracker/31639 · Telegram Post
- https://twitter.com/the_yellow_fall/status/1963417319373509011 · Twitter Post