CVE-2026-1287 | Django up to 4.2.27/5.2.10/6.0.1 annotate/aggregate/extra/values/values_list/alias sql injection (Nessus ID 297742 / WID-SEC-2026-0297)
A vulnerability was found in Django up to 4.2.27/5.2.10/6.0.1. It has been rated as critical. The affected element is the function annotate/aggregate/extra/values/values_list/alias. This manipulation causes sql injection.
This vulnerability is tracked as CVE-2026-1287. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.