CVE-2026-1312 is a SQL injection vulnerability affecting Django versions 6.0.x (before 6.0.2), 5.2.x (before 5.2.11), and 4.2.x (before 4.2.28). This flaw arises in .QuerySet.order_by() when column aliases containing periods are used with dictionary expansion in FilteredRelation. Rated Medium severity (CVSS 5.4), this vulnerability has a network attack vector and low attack complexity, allowing an authenticated attacker to achieve partial confidentiality and integrity impacts without user interaction. The FAUCET Risk Score is high at 82/100, indicating significant potential risk. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite this, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.2, < 4.2.28CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | ||
>= 5.2, < 5.2.11CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | ||
>= 6.0, < 6.0.2CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.