FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Django -- multiple vulnerabilities

Affected packages
py310-django42 < 4.2.24
py311-django42 < 4.2.24
py39-django42 < 4.2.24
py310-django51 < 5.1.12
py311-django51 < 5.1.12
py310-django52 < 5.2.6
py311-django52 < 5.2.6

Details

VuXML ID 0db8684f-8938-11f0-8325-bc2411f8eb0b
Discovery 2025-09-01
Entry 2025-09-04

Django reports:

CVE-2025-57833: Potential SQL injection in FilteredRelation column aliases.

References

CVE Name CVE-2025-57833
URL https://www.djangoproject.com/weblog/2025/sep/03/security-releases/