logo

Critical Django Flaw Allows DoS and SQL Injection Attacks

ID: 4f04c1f2-2d03-5444-8b23-ea7018b333cc

STIX ID: report--4f04c1f2-2d03-5444-8b23-ea7018b333cc

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-22

Author: Divya

...
...

The Django Software Foundation issued emergency security releases (4.2.28, 5.2.11, 6.0.2) on 2026-02-03 fixing six vulnerabilities: three high-severity SQL injection flaws impacting PostGIS raster lookups, FilteredRelation column aliases, and QuerySet.order_by(), two moderate denial-of-service issues (including ASGI duplicate header processing and HTML truncation), and one low-severity username enumeration; administrators should upgrade immediately and ensure untrusted input is properly sanitized.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.