CVE-2025-64459
CRITICAL 9.1EPSS 19.4%
An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank cyberstan for reporting this issue.
- CVSS v3.1
- 9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N - CVSS v3.1
- 9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N - EPSS
- 19.40% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2025-11-05
- Updated
- 2026-02-26
Proof-of-concept exploits (6)
- 0xCyberstan/CVE-2025-64459-Poc
- Lucas-Cyber-Security/CVE_Projects
- alxsourin/Helpdesk-Telecom-CVE-2025-64459
- joshualent/django-cve-2025-64459
- omarkurt/django-connector-CVE-2025-64459-testbed
- rafaelchriss/RedTeamBrasil-CVE-2025-64459