
PEACH
Uma estrutura de isolamento de inquilino
CVE-2025-64459 is a high-severity SQL injection vulnerability discovered in Django web framework that affects QuerySet methods and Q objects. The vulnerability was disclosed on November 5, 2025, and impacts Django versions 4.2, 5.1, 5.2, and 6.0 (beta). The flaw exists in several common Django database methods including QuerySet.filter(), QuerySet.exclude(), QuerySet.get(), and the Q() class when using dictionary expansion via the _connector keyword argument (Django Security, Security Online).
The vulnerability arises when QuerySet methods (filter(), exclude(), get()) and Q() class are used with dictionary expansion via the _connector keyword argument. The flaw occurs when the argument's contents are not properly sanitized, allowing attackers to inject malicious SQL expressions. The issue has been assigned a high severity rating according to Django's security policy (Django Security, GBHackers).
If successfully exploited, this vulnerability could allow remote attackers to modify, leak, or destroy database content, depending on application permissions and deployment configuration. Given Django's widespread use in enterprise web apps, e-commerce platforms, and APIs, this vulnerability represents a serious threat to production environments running unpatched versions (Security Online).
The Django development team has released security patches to address this vulnerability. Fixed versions are available as Django 5.2.8, 5.1.14, and 4.2.26. Users are strongly encouraged to upgrade immediately to these patched versions. The fixes have also been applied to Django's main branch and 6.0 beta (Django Security, Security Online).
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."