<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:35:25 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-13913</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-13913</link>
      <description>bdu:2025-13913</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-13913</guid>
    </item>
    <item>
      <title>BIT-django-2025-64459 — Potential SQL injection via _connector keyword argument in QuerySet and Q objects</title>
      <link>https://cve.radiocsirt.org/vuln/bit-django-2025-64459</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: django&lt;/p&gt;
&lt;p&gt;An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank cyberstan for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: django&lt;/p&gt;
&lt;p&gt;An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank cyberstan for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-django-2025-64459</guid>
    </item>
    <item>
      <title>EUVD-2026-271804</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-271804</link>
      <description>EUVD-2026-271804</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-271804</guid>
    </item>
    <item>
      <title>fkie_cve-2025-64459</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64459</link>
      <description>&lt;p&gt;An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank cyberstan for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank cyberstan for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-64459</guid>
    </item>
    <item>
      <title>GHSA-frmv-pr5f-9mcr — Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-frmv-pr5f-9mcr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django&lt;/p&gt;
&lt;p&gt;An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank cyberstan for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django&lt;/p&gt;
&lt;p&gt;An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank cyberstan for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-frmv-pr5f-9mcr</guid>
    </item>
    <item>
      <title>OESA-2025-2676 — python-django security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2676</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: python-django&lt;/p&gt;
&lt;p&gt;A high-level Python Web framework that encourages rapid development and clean, pragmatic design.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
NFKC normalization in Python is slow on Windows. As a consequence, `django.http.HttpResponseRedirect`, `django.http.HttpResponsePermanentRedirect`, and the shortcut `django.shortcuts.redirect`  were subject to a potential  denial-of-service attack via certain inputs with a very large number of Unicode characters.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Seokchan Yoon for reporting this issue.(CVE-2025-64458)&lt;/p&gt;
&lt;p&gt;An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank cyberstan for reporting this issue.(CVE-2025-64459)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: python-django&lt;/p&gt;
&lt;p&gt;A high-level Python Web framework that encourages rapid development and clean, pragmatic design.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
NFKC normalization in Python is slow on Windows. As a consequence, `django.http.HttpResponseRedirect`, `django.http.HttpResponsePermanentRedirect`, and the shortcut `django.shortcuts.redirect`  were subject to a potential  denial-of-service attack via certain inputs with a very large number of Unicode characters.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Seokchan Yoon for reporting this issue.(CVE-2025-64458)&lt;/p&gt;
&lt;p&gt;An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank cyberstan for reporting this issue.(CVE-2025-64459)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2676</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15708-1 — python311-Django4-4.2.26-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15708-1</link>
      <description>&lt;p&gt;python311-Django4-4.2.26-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-Django4-4.2.26-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15708-1</guid>
    </item>
    <item>
      <title>PYSEC-2025-108</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2025-108</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django&lt;/p&gt;
&lt;p&gt;An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank cyberstan for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django&lt;/p&gt;
&lt;p&gt;An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8.
The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank cyberstan for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2025-108</guid>
    </item>
    <item>
      <title>RHSA-2025:23069 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:23069</link>
      <description>&lt;p&gt;event-driven-ansible: Event Stream Test Mode Exposes Sensitive Headers in AAP EDA event-driven-ansible: Sensitive Internal Headers Disclosure in AAP EDA Event Streams aap-gateway: Improper Path Validation in Gateway Allows Credential Exfiltration axios: Axios DoS via lack of data size check github.com/quic-go/quic-go: quic-go Crash Due to Premature HANDSHAKE_DONE Frame django: Django SQL injection&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;event-driven-ansible: Event Stream Test Mode Exposes Sensitive Headers in AAP EDA event-driven-ansible: Sensitive Internal Headers Disclosure in AAP EDA Event Streams aap-gateway: Improper Path Validation in Gateway Allows Credential Exfiltration axios: Axios DoS via lack of data size check github.com/quic-go/quic-go: quic-go Crash Due to Premature HANDSHAKE_DONE Frame django: Django SQL injection&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:23069</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:4100-1 — Security update for python-Django</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:4100-1</link>
      <description>&lt;p&gt;Security update for python-Django&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Django&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:4100-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-64459</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-64459</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: python-django, Ubuntu:22.04:LTS: python-django, Ubuntu:24.04:LTS: python-django, Ubuntu:25.10: python-django&lt;/p&gt;
&lt;p&gt;An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank cyberstan for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: python-django, Ubuntu:22.04:LTS: python-django, Ubuntu:24.04:LTS: python-django, Ubuntu:25.10: python-django&lt;/p&gt;
&lt;p&gt;An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank cyberstan for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-64459</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2495 — Django: Mehrere Schwachstellen ermöglichen Denial of Service und SQL-Injection</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2495</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Django ausnutzen, um einen Denial of Service Angriff  und eine SQL-Injection durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Django ausnutzen, um einen Denial of Service Angriff  und eine SQL-Injection durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2495</guid>
    </item>
  </channel>
</rss>
