Django maintainers released urgent security updates addressing six vulnerabilities affecting multiple supported branches, including three high-severity SQL injection flaws and multiple denial-of-service (DoS) vectors. The issues impact Django 4.2, 5.2, 6.0, and the main development branch, with fixed releases called out as Django 4.2.28, 5.2.11, and 6.0.2.
The most severe fixes cover SQL injection paths that can allow execution of arbitrary SQL: CVE-2026-1207 affects PostGIS users via raster lookups on GIS fields when untrusted input is used as a band index; CVE-2026-1287 involves FilteredRelation SQL injection through column aliases containing control characters when crafted dictionaries are expanded into QuerySet methods (e.g., annotate(), aggregate(), values()); and CVE-2026-1312 targets QuerySet.order_by() with FilteredRelation via column aliases containing periods. DoS fixes include CVE-2025-14550 (resource exhaustion via repeated/duplicate headers in ASGI deployments) and CVE-2026-1285 (DoS in django.utils.text.Truncator HTML methods), alongside a low-severity timing issue CVE-2025-13473 that can enable username enumeration in a mod_wsgi authentication handler.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Django published fixed releases 6.0.2, 5.2.11, and 4.2.28, along with GitHub changesets for affected branches. The advisory urged immediate upgrades, especially for deployments using PostGIS, ASGI servers, or FilteredRelation-based queries.
The Django development team issued urgent security updates addressing six flaws affecting Django 4.2, 5.2, 6.0, and the main development branch. The issues included three high-severity SQL injection vulnerabilities, multiple denial-of-service risks, and a low-severity username-enumeration timing issue in mod_wsgi authentication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.