Name
CVE-2025-57833
Description
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().
CWEs
Published Date
Updated Date
Workaround
-
Advisories
https://docs.djangoproject.com/en/dev/releases/security/Vendor Advisory
https://groups.google.com/g/django-announceVendor Advisory
Analysis#
Vulnerability Ratings#
7.1
CVSSv31
8.1
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
python3-django (yocto:kirkstone)
#
Title
Author
Resolve
1
Fixed CVE-2025-57833 -- Protected FilteredRelation against
Jake Howard <git@theorangeone.net>
CVE-2025-57833
python3-django (yocto:kirkstone)
#
Title
Author
Resolve
1
Fixed CVE-2025-57833 -- Protected FilteredRelation against
Jake Howard <git@theorangeone.net>
CVE-2025-57833
python3-django (yocto:kirkstone)
#
Title
Author
Resolve
1
Fixed CVE-2025-57833 -- Protected FilteredRelation against
Jake Howard <git@theorangeone.net>
CVE-2025-57833