References https://github.com/django/django/commit/4f5b58f5cd3c57fee9972ab074f8dc6895d8f387 https://www.sentinelone.com/vulnerability-database/cve-2024-42005/ https://nosec.org/home/detail/2831.html https://github.com/advisories/GHSA-6r97-cj55-9hrq https://github.com/django/django/commit/7deeabc7c7526786df6894429ce89a9c4b614086 https://hackerone.com/reports/2588426 https://github.com/advisories/GHSA-pv4p-cwwg-4rph https://cloud.tencent.com/developer/article/1718051 https://github.com/django/django/commit/f4af67b9b41e0f4c117a8741da3abbd1c869ab28 https://github.com/django/django/commit/32ebcbf2e1fe3e5ba79a6554a167efce81f7422d https://bugzilla.redhat.com/show_bug.cgi?id=1734417 https://docs.djangoproject.com/zh-hans/releases/security/ https://github.com/django/django/commit/f74b3ae3628c26e1b4f8db3d13a91d52a833a975 https://bugzilla.suse.com/show_bug.cgi?id=1142883 https://www.sherlockforensics.com/security/pypi/django.html
Related VulnerabilitiesPoCCVE-2026-26265: Discourse - Private User Field Disclosure via Directory Items IDOR泛微-Ecology10 getFieldValueFun SQL注入漏洞用友 GRP-U8Cloud /jmreport/queryFieldBySql Freemarker 命令执行漏洞孚盟云 CRM /Ajax/upload.ashx DownLoadFieldAttch SQL 注入漏洞华测监测预警系统dataField参数存在SQL注入PoCCVE-2024-12873: Custom Field Manager WordPress - Cross-Site ScriptingPoCCVE-2026-1207: Django RasterField - SQL InjectionDjango 需授权 SQL注入漏洞PoCwp-acf-fpd: Advanced Custom Fields (ACF) - Full Path DisclosurePoCCVE-2025-13486: Advanced Custom Fields Extended < 0.9.2 - Remote Code ExecutionDjango 未授权 SQL注入漏洞