Package: python-django
Version: 2:2.2.28-1~deb11u7
X-Debbugs-CC: [email protected]
Severity: grave
Tags: security

Hi,

The following vulnerability was published for python-django.

CVE-2025-57833[0]: Potential SQL injection in FilteredRelation
 column aliases FilteredRelation was subject to SQL injection in
 column aliases, using a suitably crafted dictionary, with
 dictionary expansion, as the **kwargs passed QuerySet.annotate()
 or QuerySet.alias().


For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-57833
    https://www.cve.org/CVERecord?id=CVE-2025-57833
    https://www.djangoproject.com/weblog/2025/sep/03/security-releases/


Regards,

-- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      [email protected] / chris-lamb.co.uk
       `-

Reply via email to