Feed/CVE-2025-64459
CVE-2025-64459CRITICALCVSS 9.1

CVE-2025-64459

Published Nov 5, 2025·Updated Jun 17, 2026

NVD Description

An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank cyberstan for reporting this issue.

Public Exploits & PoCs10 found

PoC: CVE-2025-64459

CVE-2025-64459 vulnerable by design app

PoC: RedTeamBrasil-CVE-2025-64459

NEO-SQLi — exploit Django _connector SQL Injection (CVE-2025-64459) | canal RedTeam Brasil

PoC: django-cve-2025-64459

demo application showing off SQL Injection exploit in django 5.2.7

PoC: CVE-2025-64459-hunter

CVE-2025-64459-hunter

PoC: CVE-2025-64459-Exploit-PoC

CVE-2025-64459-Exploit-PoC

PoC: CVE-2025-64459-Exploit-Fix

CVE-2025-64459-Exploit-Fix

PoC: CVE-2025-64459-Poc

Vulnerability: SQL Injection via QuerySet and Q() keyword argument unpacking. CVE ID: CVE-2025-64459 Severity: Critical (CVSS 9.1) Affected Versions: Django 5.1 < 5.1.14, 4.2 < 4.2.26, and 5.2 < 5.2.8. Researcher: Cyberstan (University of Warwick)

PoC: django-connector-CVE-2025-64459-testbed

A self-contained testbed for Django CVE-2025-64459. Demonstrates QuerySet.filter() parameter injection via dictionary expansion using Docker.

PoC: Blackash-CVE-2025-64459

CVE-2025-64459

PoC: CVE-2025-64459

check if vulnerable python-django version to CVE-2025-64459 bug

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free