An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. (CVE-2025-57833)
A SQL injection vulnerability exists in Django versions 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. The issue arises in the FilteredRelation feature when column aliases are constructed using a crafted dictionary passed as **kwargs to QuerySet.annotate() or QuerySet.alias(). This vulnerability allows injection via SQL column aliases. Red Hat has issued an important security advisory with patches available to address this issue.
AI Analysis
Technical Summary
CVE-2025-57833 describes a SQL injection vulnerability in Django's FilteredRelation feature affecting versions 4.2 prior to 4.2.24, 5.1 prior to 5.1.12, and 5.2 prior to 5.2.6. The vulnerability occurs when a specially crafted dictionary is used with dictionary expansion as keyword arguments to QuerySet.annotate() or QuerySet.alias(), allowing injection in SQL column aliases. Red Hat Product Security has released an advisory (RHSA-2025:17500) detailing this issue and providing patches for affected packages, including python-django 3.2.12-9.el9ost for Red Hat OpenStack Services on OpenShift 18.0. The advisory rates the security impact as Important and confirms that patches are available.
Potential Impact
The vulnerability allows SQL injection via column aliases in Django's FilteredRelation, potentially enabling attackers to manipulate SQL queries. This could lead to unauthorized data access or modification depending on the application's database permissions and usage of the affected Django versions. The Red Hat advisory classifies the impact as Important (high severity). No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Patches are available and should be applied promptly. Users should upgrade Django to versions 4.2.24 or later, 5.1.12 or later, and 5.2.6 or later as appropriate. For Red Hat OpenStack Services on OpenShift 18.0, updated python-django packages are provided. Refer to the Red Hat advisory RHSA-2025:17500 and https://access.redhat.com/articles/11258 for detailed update instructions. No additional mitigation beyond applying the official patches is indicated.
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. (CVE-2025-57833)
Description
A SQL injection vulnerability exists in Django versions 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. The issue arises in the FilteredRelation feature when column aliases are constructed using a crafted dictionary passed as **kwargs to QuerySet.annotate() or QuerySet.alias(). This vulnerability allows injection via SQL column aliases. Red Hat has issued an important security advisory with patches available to address this issue.
Affected software
pkg:rpm/redhat/python-djangoRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-57833 describes a SQL injection vulnerability in Django's FilteredRelation feature affecting versions 4.2 prior to 4.2.24, 5.1 prior to 5.1.12, and 5.2 prior to 5.2.6. The vulnerability occurs when a specially crafted dictionary is used with dictionary expansion as keyword arguments to QuerySet.annotate() or QuerySet.alias(), allowing injection in SQL column aliases. Red Hat Product Security has released an advisory (RHSA-2025:17500) detailing this issue and providing patches for affected packages, including python-django 3.2.12-9.el9ost for Red Hat OpenStack Services on OpenShift 18.0. The advisory rates the security impact as Important and confirms that patches are available.
Potential Impact
The vulnerability allows SQL injection via column aliases in Django's FilteredRelation, potentially enabling attackers to manipulate SQL queries. This could lead to unauthorized data access or modification depending on the application's database permissions and usage of the affected Django versions. The Red Hat advisory classifies the impact as Important (high severity). No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Patches are available and should be applied promptly. Users should upgrade Django to versions 4.2.24 or later, 5.1.12 or later, and 5.2.6 or later as appropriate. For Red Hat OpenStack Services on OpenShift 18.0, updated python-django packages are provided. Refer to the Red Hat advisory RHSA-2025:17500 and https://access.redhat.com/articles/11258 for detailed update instructions. No additional mitigation beyond applying the official patches is indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:17500
- Cve Count
- 1
Threat ID: 6a419cb227e9c79719abbc7c
Added to database: 06/28/2026, 22:14:10 UTC
Last enriched: 08/18/2026, 14:49:39 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.