CVE-2025-64459General(djangoproject / django)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch djangoproject django systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank cyberstan for reporting this issue.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • django

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • General: 6 classified signals
  • Peaked 5d ago at 2 mentions (2026-02-05); latest day: 2
  • 11 total mentions across 9 days

Affected systems

Products
django

Deep dive

Activity timeline11 mentions / 9d
01122Mentions · 2026-02-01: 1Mentions · 2026-02-03: 1Mentions · 2026-02-04: 1Mentions · 2026-02-05: 2Mentions · 2026-02-25: 1Mentions · 2026-03-04: 1Mentions · 2026-04-15: 1Mentions · 2026-04-22: 1Mentions · 2026-08-25: 2Active Exploitation · 2026-02-05: 1Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-02-05: 2Technical Details · 2026-04-22: 1Technical Details · 2026-08-25: 102-0102-0302-0402-0502-2503-0404-1504-2208-25
Signal classification5 categories
General
654.5%
Patch
218.2%
Active Exploitation
19.1%
Disclosure
19.1%
False Positive
19.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-011
General1
2026-02-031
General1
2026-02-041
General1
2026-02-052
Active Exploitation1Patch1
2026-02-251
General1
2026-03-041
General1
2026-04-151
General1
2026-04-221
Disclosure1
2026-08-252
False Positive1Patch1
Full discourse11 posts
  • Cloudflare Changelog@CFchangelog
    Active Exploitation

    🛡️ New WAF detections are LIVE! We're now blocking exploits for CVE-2025-64459 (Django SQLi) & CVE-2025-24893 (XWiki RCE). Keeping your apps secure is our priority! 🚀 https://developers.cloudflare.com/changelog/2026-02-02-waf-release/

    Post summary

    Cloudflare’s WAF now blocks active exploitation attempts for CVE‑2025‑64459 (Django SQLi) and CVE‑2025‑24893 (XWiki RCE).

    0202021.1K
    1.1K followersView on X
  • Kurimochi@kurimochi_
    General

    I just completed Django: CVE-2025-64459 room on TryHackMe! Explore and learn about the Django CVE-2025-64459 vulnerability. https://tryhackme.com/room/djangocve202564459?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=677f8f3b20dd2438669279b5 #tryhackme via @tryhackme

    Post summary

    The post promotes a TryHackMe training room for Django CVE‑2025‑64459 but provides no technical, exploit, or mitigation details.

    00040174
    891 followersView on X
  • Aazim Anish 🦇@aazim_anish
    General

    Day 5: Need to level up my DSA clean code comes from strong fundamentals. Tried many times before and failed. This time, no LeetCode rush. Started Grokking Algorithms by Aditya Y. Bhargava. Finished the intro and began binary search. Also replicated Django CVE-2025-64459.

    Post summary

    The post merely notes that the author replicated a Django CVE, providing no further technical or operational details.

    0004071
    337 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical SQL injection (CVE-2025-64459) affects #Django via the `_connector` argument. Review code for exposed `QuerySet`/`Q` object usage. #SQLi #infosec https://www.pulsepatch.io/posts/cve-2025-64459-django-sql-injection-connector

    Post summary

    The tweet announces CVE-2025-64459, a critical SQL injection vulnerability in Django stemming from the `_connector` argument. It stresses reviewing code for exposed QuerySet or Q object usage but does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    00002250
    12 followersView on X
  • CVE Brief@DailyCVEBrief
    False Positive

    LOOK BACK — CVE-2025-64459 is filed everywhere as a 9.1 critical Django SQL injection. Django, the CNA, published no CVSS at all. NVD assigned none. The 9.1 is a CISA enrichment score, sitting in the same record that logs exploitation: none. https://t.co/PuF3760fgO

    Post summary

    The tweet challenges the reported CVSS severity of CVE‑2025‑64459, points out no active exploitation, and suggests the vulnerability may be less consequential than the high score implies.

    1000040
    29 followersView on X
  • Aazim Anish 🦇@aazim_anish
    General

    Day 3: Started reading about Django CVE-2025-64459 understood the exploit, will try to replicate it tomorrow. Finished the Atomic Habits intro. Revisited Foundry basics: Anvil setup and Forge deployment. No big steps. Step by step.

    Post summary

    The user is reviewing CVE‑2025‑64459 and plans to replicate the exploit but provides no concrete technical details, PoC, or evidence of active exploitation.

    00010271
    337 followersView on X
  • CVE Brief@DailyCVEBrief
    Patch

    Nine months on: no KEV listing, no observed exploitation, and a fix Django deliberately scoped narrower than reporters wanted. Full Look Back on where the _connector key came from: https://cvebrief.com/cve/CVE-2025-64459/ https://t.co/Dp56ho6VUw

    Post summary

    After nine months the CVE-2025-64459 has seen no KEV listing or exploitation, and a narrowly scoped Django patch has been issued.

    0000027
    29 followersView on X
  • Sun4lower@LittleSun4lower
    General

    I just completed Django: CVE-2025-64459 room on TryHackMe! Explore and learn about the Django CVE-2025-64459 vulnerability. https://tryhackme.com/room/djangocve202564459?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #consistency

    Post summary

    The tweet promotes a TryHackMe learning room about Django CVE-2025‑64459, but provides no technical details, PoC, or exploitation evidence.

    00000278
    6 followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    General

    I just completed Django: CVE-2025-64459 room on TryHackMe! Explore and learn about the Django CVE-2025-64459 vulnerability. https://tryhackme.com/room/djangocve202564459?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The tweet promotes a TryHackMe room for learning about Django CVE-2025-64459, without providing exploitation details, patches, or technical specifics.

    0000070
  • Roman@mrBr4un
    General

    I just completed Django: CVE-2025-64459 room on TryHackMe! Explore and learn about the Django CVE-2025-64459 vulnerability. https://tryhackme.com/room/djangocve202564459?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=68639866ce8287add0b55c97 #tryhackme через @tryhackme

    Post summary

    The post announces completion of a TryHackMe room about CVE-2025-64459, with no further technical or exploit details.

    0000041
    57 followersView on X
  • Miguel Vera@mveracf
    Patch

    🛡️ New WAF detections are here! Protecting against critical vulnerabilities like CVE-2025-64459 (Django SQLi) & CVE-2025-24893 (XWiki RCE). We've automatically updated to Block—stay secure! 🚀 https://developers.cloudflare.com/changelog/2026-02-02-waf-release/

    Post summary

    Cloudflare’s latest WAF release automatically blocks traffic targeting CVE-2025-64459 (Django SQLi) and CVE-2025-24893 (XWiki RCE), providing immediate protection for affected sites.

    0000062
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdjangoprojectdjango---

Explore more