The Django development team released a security update addressing two critical vulnerabilities: a high-severity SQL injection flaw (CVE-2025-64459) and a denial-of-service (DoS) bug (CVE-2025-64458). The SQL injection vulnerability, present in Django's Object-Relational Mapper (ORM), could allow attackers to manipulate database queries and compromise data integrity if exploited. The DoS vulnerability could enable attackers to disrupt application availability by sending specially crafted requests.
Security researchers highlighted that these flaws expose underlying risks in Django's ORM, which is widely trusted for its built-in security features. The incident underscores the importance of regular security reviews and prompt patching, even for mature frameworks. Organizations using Django are strongly advised to apply the latest security updates to mitigate these threats and reassess their reliance on default ORM protections.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A follow-up security analysis described CVE-2025-57833, an alias-construction flaw involving FilteredRelation with QuerySet.annotate() or QuerySet.alias() that could enable SQL-injection-style manipulation when alias names come from untrusted input. The article also connected this issue with prior Django ORM and DoS bugs, urging code audits and a 'trust but verify' approach to framework defaults.
The Django team issued a security update addressing CVE-2025-64459, a high-severity SQL injection vulnerability, and CVE-2025-64458, a denial-of-service bug. The update was reported as the latest Django security release and advised users to upgrade to patched versions.
Django released fixes for CVE-2024-42005, a SQL injection issue affecting QuerySet.values() and QuerySet.values_list() on models with JSONField when crafted JSON object keys were passed as positional arguments. The flaw showed that alias construction in the ORM could be abused under specific developer usage patterns.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
foresiet.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.