Critical Django Flaw Allows DoS and SQL Injection Attacks
ID: 4f04c1f2-2d03-5444-8b23-ea7018b333cc
STIX ID: report--4f04c1f2-2d03-5444-8b23-ea7018b333cc
Feed Name: GBHackers
The Django Software Foundation issued emergency security releases (4.2.28, 5.2.11, 6.0.2) on 2026-02-03 fixing six vulnerabilities: three high-severity SQL injection flaws impacting PostGIS raster lookups, FilteredRelation column aliases, and QuerySet.order_by(), two moderate denial-of-service issues (including ASGI duplicate header processing and HTML truncation), and one low-severity username enumeration; administrators should upgrade immediately and ensure untrusted input is properly sanitized.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
