CVE-2025-64459

CVE-2025-64459: Potential SQL injection via _connector keyword argument in QuerySet and Q objects

Vendor Djangoproject
Product Django
Weakness CWE-89 · SQLi
Published November 5, 2025
Last update February 26, 2026

CVSS base score

What the vulnerability does

01Description

An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank cyberstan for reporting this issue.

Key dates

02Disclosure timeline

November 5, 2025 CVE published
February 26, 2026 Record updated