USN-7859-1: Django vulnerabilities
USN-7859-1: Django vulnerabilities
Publication date: 5 November 2025
Overview: Django could be made to run programs if it received specially crafted network traffic.
Packages
python-django - High-level Python web development framework
Details
It was discovered that Django incorrectly handled certain characters in
queries. An attacker could possibly use this issue to execute arbitrary SQL
commands.
Update instructions
The problem can be corrected by updating your system to the following package versions:
25.10 questing
- python3-django – 3:5.2.4-1ubuntu2.1
25.04 plucky
- python3-django – 3:4.2.18-1ubuntu1.6
24.04 LTS noble
- python3-django – 3:4.2.11-1ubuntu1.12
22.04 LTS jammy
- python3-django – 2:3.2.12-2ubuntu1.23
20.04 LTS focal
- python3-django – 2:2.2.12-1ubuntu0.29+esm5

