GHSA-6w2r-r2m5-xq5w
GitHub Security Advisory
⚠ Unreviewed
HIGH
Has CVE
Advisory Details
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: September 9, 2025 6:37 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.