CVE-2026-1312 is a high-severity SQL injection vulnerability in Django affecting QuerySet.order_by() when column aliases containing periods are used together with FilteredRelation and a suitably crafted dictionary passed via dictionary expansion. The flaw arises from unsafe handling of crafted column aliases in this query-construction path, allowing attacker-controlled input to influence generated SQL under specific application usage patterns. Affected versions are Django 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Older unsupported series, including 5.0.x, 4.1.x, and 3.2.x, were not evaluated and may also be affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small Django proof-of-concept application built to reproduce CVE-2026-1312, a SQL injection issue in Django ORM query construction. It is not an exploit framework module; it is a standalone demo environment with a vulnerable web endpoint and supporting Docker/devcontainer files. Repository structure: the root contains standard Django project files (manage.py, web/ project config, vuln/ app) plus .devcontainer and VS Code tasking for easy local reproduction. The vuln app defines two models, Author and Book, with seeded sample data in migrations. Routing is minimal: web/urls.py includes vuln.urls under /book/, and vuln/urls.py exposes /book/search. Core exploit logic is in vuln/views.py, specifically Books.get(). The handler reads the attacker-controlled GET parameter 'name', stores it in 'crafted', then uses it directly in Book.objects.alias(**{crafted: relation}).order_by(crafted) with a FilteredRelation('author'). This unsafe pattern allows crafted input containing dotted alias syntax and SQL fragments to influence the generated ORDER BY clause. The README demonstrates a PostgreSQL time-based payload, 'vuln_book.id,pg_sleep(2)', which results in SQL resembling ORDER BY ("vuln_book".id,pg_sleep(2)) ASC. The effect is a delayed response, confirming SQL injection in the ORM-generated query. Capabilities: the code demonstrates remote, unauthenticated SQL injection over HTTP through a query parameter. The included payload is a time-based blind SQLi proof of concept rather than a full post-exploitation chain. No reverse shell, file write, or credential dumping automation is implemented, though the seeded database includes an Author.password field that could be a target for further manual exploitation. Operational details: the app is configured for PostgreSQL, with default containerized database host 'db' and port 5432. The development server listens on 0.0.0.0:8086 and is exposed as localhost:8086. The README provides reproduction steps using VS Code devcontainers and database migrations. Overall, this repository's purpose is to reproduce and validate the vulnerability, not to provide a weaponized exploit toolkit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A SQL injection vulnerability in Django involving QuerySet.order_by(), dotted column aliases, and crafted dictionary expansion in FilteredRelation. Affected versions are Django 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Unsupported branches were not evaluated and may also be affected. The reference assigns a CVSS v3 base score of 8.5, indicating high severity.
A SQL injection vulnerability in Django via crafted column aliases in QuerySet.order_by().
A SQL injection vulnerability in Django via crafted column aliases in QuerySet.order_by().
A SQL injection vulnerability in Django's QuerySet.order_by() involving crafted column aliases used with FilteredRelation. It affects Django 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28; older unsupported series may also be affected.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.