A high-severity SQL injection vulnerability tracked as CVE-2025-64459 was disclosed in the Django web framework, affecting QuerySet.filter(), QuerySet.exclude(), QuerySet.get(), and the Q() class when a suitably crafted dictionary is expanded into the _connector argument. The issue received a CVSS 9.1 score in the CVE record, while Red Hat rated it Important with a CVSS v3 8.3, citing vendor-specific scoring differences and noting that exploitation impact is limited to the effective user scope of the running process.
Red Hat reported that no acceptable mitigation is currently available and identified multiple affected products and components, including packages in Red Hat Ansible Automation Platform 2.5 for RHEL 8. The company said fixes were released for impacted offerings, including remediation delivered through advisory RHSA-2025:23069, underscoring the need for organizations running Django-based applications or affected Red Hat packages to prioritize patching.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
On December 10, 2025, Red Hat issued RHSA-2025:23069 to fix CVE-2025-64459 in multiple Red Hat Ansible Automation Platform 2.5 for RHEL 8 components, including ansible-builder, ansible-runner, ansible-navigator, and automation-controller.
Red Hat marked its CVE-2025-64459 entry public on November 5, 2025, describing the Django flaw as an Important SQL injection issue and noting no acceptable mitigation was available at that time.
Django security release information dated November 5, 2025 identified CVE-2025-64459 as a SQL injection vulnerability affecting QuerySet.filter(), QuerySet.exclude(), QuerySet.get(), and the Q() class when a crafted dictionary is expanded into the _connector argument.
Red Hat last modified its CVE-2025-64459 entry on March 18, 2026, reflecting an update to the vendor's vulnerability record for the Django SQL injection issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.