CVE-2025-57833HIGH 8.1EPSS p96.4%

CVE-2025-57833CVE-2025-57833

Description

An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().

Scoring

CVSS 3.18.1 (HIGH)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS15.60% probability of exploitation · percentile 96.4% · 2026-06-18T12:00:27Z
Published2025-09-03
Last modified2025-11-04

Underlying weaknesses· 1

CWE-89

References

  1. https://docs.djangoproject.com/en/dev/releases/security/
  2. https://groups.google.com/g/django-announce
  3. https://medium.com/@EyalSec/django-unauthenticated-0-click-rce-and-sql-injection-using-default-configuration-059964f3f898
  4. https://www.djangoproject.com/weblog/2025/sep/03/security-releases/
  5. http://www.openwall.com/lists/oss-security/2025/09/03/3
  6. https://lists.debian.org/debian-lts-announce/2025/09/msg00017.html

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')cwe-890%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-59681
CVE
CVE-2025-64459
CVE
CVE-2026-4277
CVE
CVE-2025-48383
CVE
CVE-2025-27617
CVE
CVE-2026-6873
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.