CVE-2026-1312

EUVD-2026-5236
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
`.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, with dictionary expansion, used in `FilteredRelation`.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Solomon Kebede for reporting this issue.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 53.85%
Affected Products (NVD)
VendorProductVersion
djangoprojectdjango
4.2 ≤
𝑥
< 4.2.28
djangoprojectdjango
5.2 ≤
𝑥
< 5.2.11
djangoprojectdjango
6.0 ≤
𝑥
< 6.0.2
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8
0:4.2.28-1.el8ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9
0:4.2.28-1.el9ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9
0:4.2.28-1.el9ap ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.16 for RHEL 8
0:4.2.28-0.1.el8pc ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.16 for RHEL 9
0:4.2.28-0.1.el9pc ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.17 for RHEL 9
0:3.14.0.14-1.el9sat ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.17 for RHEL 9
0:0.1.23-0.3.el9pc ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.17 for RHEL 9
0:1.2.0-0.1.el9pc ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.17 for RHEL 9
0:4.2.28-0.1.el9pc ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.17 for RHEL 9
0:2.22.3-1.el9pc ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.17 for RHEL 9
0:3.27.10-2.el9pc ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.17 for RHEL 9
0:1.5.1-1.el9sat ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.17 for RHEL 9
0:0.4.3-1.el9sat ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.17 for RHEL 9
0:4.16.0.14-1.el9sat ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.17 for RHEL 9
0:0.13.0-1.el9sat ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.17 for RHEL 9
0:6.17.7-1.el9sat ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.17 for RHEL 9
0:0.0.3-4.el9sat ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.18 for RHEL 9
0:4.2.30-1.el9pc ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.5
1772214630 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6
1772552788 ≤
𝑥
< *
ADP
Red HatRed Hat Discovery 2
1770913597 ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.18
1773451075 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
python-django
bookworm
3:3.2.25-0+deb12u3
fixed
bookworm (security)
3:3.2.25-0+deb12u4
fixed
bullseye
vulnerable
bullseye (security)
2:2.2.28-1~deb11u13
fixed
forky
3:5.2.16-1
fixed
sid
3:5.2.17-1
fixed
trixie
3:4.2.28-0+deb13u2
fixed
trixie (security)
3:4.2.28-0+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-django
bionic
ignored
focal
ignored
jammy
ignored
noble
Fixed 3:4.2.11-1ubuntu1.14
released
questing
Fixed 3:5.2.4-1ubuntu2.3
released
trusty
ignored
xenial
ignored