A disclosed vulnerability in the Django web framework, tracked as CVE-2025-57833, allows SQL injection through FilteredRelation column aliases when a suitably crafted dictionary is expanded as **kwargs into QuerySet.annotate() or QuerySet.alias(). The issue is classified as CWE-89 and affects applications that pass attacker-controlled input into those ORM methods, potentially enabling unauthorized database query manipulation.
Red Hat rated the flaw Important with a CVSS v3 score of 7.1, while noting that the NVD assigned a higher 8.1 score. Red Hat also said there was no acceptable mitigation at disclosure and identified multiple affected products and components, which were later addressed through security errata released in September and October 2025.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:16403 and RHSA-2025:16404 to fix CVE-2025-57833 in Red Hat Ansible Automation Platform 2.4 for RHEL 8 and RHEL 9, including python3x-django, python-django, and lightspeed-related components.
Red Hat made its CVE-2025-57833 entry public, describing an SQL injection vulnerability in Django involving FilteredRelation column aliases. The flaw can be triggered via a crafted dictionary expanded as **kwargs to QuerySet.annotate() or QuerySet.alias().
Red Hat last modified its CVE-2025-57833 entry, reflecting an update to the vendor advisory record for the Django SQL injection issue.
Red Hat published RHSA-2025:17499 and RHSA-2025:17498 to remediate CVE-2025-57833 in Red Hat OpenStack Platform 16.2 and 17.1, affecting python-django20 and python-django packages.
Red Hat released RHSA-2025:16487 and RHSA-2025:16514 to address CVE-2025-57833 in Red Hat Ansible Automation Platform 2.5 for RHEL 8 and RHEL 9, covering automation-controller, python3.11-django, and lightspeed-related packages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.