CVE-2025-59681

critical

Description

An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injection in column aliases, when using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to these methods (on MySQL and MariaDB).

References

https://www.djangoproject.com/weblog/2025/oct/01/security-releases/

https://groups.google.com/g/django-announce

https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-32691

https://docs.djangoproject.com/en/dev/releases/security/

http://www.openwall.com/lists/oss-security/2025/10/01/3

Details

Source: Mitre, NVD

Published: 2025-10-01

Updated: 2025-11-04

Named Vulnerability: GHSA-hpr9-3m2g-3j9p

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.0001