critical
CVE-2022-28346
Django SQL injection via crafted dictionary expansion in QuerySet.annotate()/aggregate()
- Severity
- critical
- Affected product
- Django
- Affected versions
- Django ≥ 2.2, < 2.2.28
- Affected versions
- Django ≥ 3.2, < 3.2.13
- Affected versions
- Django ≥ 4.0, < 4.0.4
- Fixed in
- Django 2.2.28
- Fixed in
- Django 3.2.13
- Fixed in
- Django 4.0.4
- Added to NewScan
- 2026-08-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Django from its response and reports this CVE when the detected version falls inside the affected range below.
Backfilled 2026-08-02 (docs/todo.md item 1).
COMPONENT VERSION RANGE
NewScan fingerprints Django from its response and reports this CVE when the detected version falls inside the affected range below.
Backfilled 2026-08-02 (docs/todo.md item 1).
COMPONENT VERSION RANGE
NewScan fingerprints Django from its response and reports this CVE when the detected version falls inside the affected range below.
Backfilled 2026-08-02 (docs/todo.md item 1).
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →