CVE-2026-1312Patch(djangoproject / django)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch djangoproject django systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, with dictionary expansion, used in `FilteredRelation`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Solomon Kebede for reporting this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • django

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-03); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
django

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-03: 1Mentions · 2026-02-08: 1Mentions · 2026-02-15: 1Patch / Workaround · 2026-02-08: 1Patch / Workaround · 2026-02-15: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-08: 1Technical Details · 2026-02-15: 102-0302-0802-15
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-031
Disclosure1
2026-02-081
Patch1
2026-02-151
Patch1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Patch

    More of the CVEs fixed in Django: CVE-2026-1285: Potential DoS in django.utils.text.Truncator HTML methods CVE-2026-1287: Potential SQL injection in column aliases via control characters CVE-2026-1312: Potential SQL injection via QuerySet.order_by and FilteredRelation

    Post summary

    Django has fixed three CVEs—two SQL injection flaws and a potential DoS—without providing PoC or exploitation details.

    00040377
    4.4K followersView on X
  • DDS@Docker/Python/Django/ASP.NET/CSharpとガーデニングも好き@DDSFILT
    Patch

    Djangoのセキュリティアップデートが出てますね。5.2.11と6.0.2にアップデートしましょう。 今回の脆弱性のうち、SQLインジェクション脆弱性(CVE-2026-1312)に関連してorder_by()の安全な書き方を記事にしましたので、ぜひ、ご一読ください。 https://tomomori.net/django5-2-11%e3%81%8a%e3%82%88%e3%81%b36-0-2%e3%82%bb%e3%82%ad%e3%83%a5%e3%83%aa%e3%83%86%e3%82%a3%e3%82%a2%e3%83%83%e3%83%97%e3%83%87%e3%83%bc%e3%83%88%e3%81%a8order_by%e3%81%ae%e5%ae%89%e5%85%a8/

    Post summary

    The post advises users to upgrade Django to 5.2.11 or 6.0.2 to patch CVE‑2026‑1312, a SQL injection flaw, and links to an article detailing safe usage of order_by().

    00120207
    641 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1312 An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing p… https://www.cve.org/CVERecord?id=CVE-2026-1312

    Post summary

    CVE‑2026‑1312 is a SQL injection flaw in Django’s QuerySet.order_by() affecting versions 4.2, 5.2, and 6.0; the description provides technical details but no PoC, patch, or exploitation evidence.

    00000154
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdjangoprojectdjango---

Explore more