← Vulnerability feed

Vulnerability record · CVE-2020-7471 · published 3 February 2020

CVE-2020-7471: Django StringAgg delimiter SQL injection

Djangoproject · Django

Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allow SQL injection when untrusted data is used as the delimiter of a contrib.postgres.aggregates.StringAgg instance. A crafted delimiter breaks escaping and injects malicious SQL, which matters because such delimiters are commonly taken from user input in data-export features.

9.8 CVSS 3.1 Critical EPSS 66% · top 0.8% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References
17 Jun 2026Last modified by NVD

Description

Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with a user-specified column delimiter). By passing a suitably crafted delimiter to a contrib.postgres.aggregates.StringAgg instance, it was possible to break escaping and inject malicious SQL.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 9.8 and a 99.2nd percentile EPSS score indicate severe, likely-exploitable SQL injection, though there is no KEV listing or documented in-the-wild use.

What it is

Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allow SQL injection when untrusted data is used as the delimiter of a contrib.postgres.aggregates.StringAgg instance. A crafted delimiter breaks escaping and injects malicious SQL, which matters because such delimiters are commonly taken from user input in data-export features.

Impact

An attacker can inject arbitrary SQL into queries built with StringAgg, potentially reading or modifying database contents and, depending on database privileges, executing database-side operations.

Attack surface

Reached over the network through any Django application that passes user-controlled data as a StringAgg delimiter, such as a download endpoint with a user-specified column delimiter. The CVSS vector indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware group use is documented, but EPSS is 0.65575 (99.2nd percentile), indicating a high modeled likelihood of exploitation. References include a vendor patch commit and multiple vendor advisories.

What to do

  • Upgrade Django to 1.11.28, 2.2.10, 3.0.3 or later; the patch commit is eb31d845323618d688ad429479c6dda973056136.
  • Apply distribution updates (Debian DSA-4629, Ubuntu USN-4264-1, Gentoo GLSA 202004-17, Fedora) where Django is packaged.
  • Never pass untrusted input directly as a StringAgg delimiter; validate or whitelist allowed delimiter values.
  • Audit application code for StringAgg usage with user-supplied delimiters and replace with parameterized or fixed delimiters.
  • Restrict database account privileges for the Django application to limit the impact of successful injection.

Detection

  • Search application code and logs for StringAgg usage where the delimiter originates from request parameters.
  • Monitor database query logs for anomalous SQL in aggregate or string_agg statements.
  • Alert on requests to data-export or download endpoints that carry unusual delimiter parameter values.
  • Review database error logs for syntax errors or unexpected query patterns tied to export functionality.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2020/02/03/1 Mailing ListThird Party Advisory
https://docs.djangoproject.com/en/3.0/releases/security/ Vendor Advisory
https://github.com/django/django/commit/eb31d845323618d688ad429479c6dda973056136 PatchThird Party Advisory
https://groups.google.com/forum/#%21topic/django-announce/X45S86X5bZI
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4A2AP4T7RKPBCLTI2NNQG3T
https://seclists.org/bugtraq/2020/Feb/30
https://security.gentoo.org/glsa/202004-17
https://security.netapp.com/advisory/ntap-20200221-0006/
https://usn.ubuntu.com/4264-1/
https://www.debian.org/security/2020/dsa-4629
https://www.djangoproject.com/weblog/2020/feb/03/security-releases/ Vendor Advisory
https://www.openwall.com/lists/oss-security/2020/02/03/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2020/02/03/1 Mailing ListThird Party Advisory
https://docs.djangoproject.com/en/3.0/releases/security/ Vendor Advisory
https://github.com/django/django/commit/eb31d845323618d688ad429479c6dda973056136 PatchThird Party Advisory
https://groups.google.com/forum/#%21topic/django-announce/X45S86X5bZI
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4A2AP4T7RKPBCLTI2NNQG3T
https://seclists.org/bugtraq/2020/Feb/30
https://security.gentoo.org/glsa/202004-17
https://security.netapp.com/advisory/ntap-20200221-0006/
https://usn.ubuntu.com/4264-1/
https://www.debian.org/security/2020/dsa-4629
https://www.djangoproject.com/weblog/2020/feb/03/security-releases/ Vendor Advisory
https://www.openwall.com/lists/oss-security/2020/02/03/1 Mailing ListThird Party Advisory

Track CVE-2020-7471 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-0474Canonical ubuntu linux vulnerabilityThe (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x befor…EPSS 4.9%9.8CVE-2026-4277Djangoproject django missing authorization vulnerabilityAn issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated o…EPSS 0.60%9.8CVE-2025-59681Djangoproject django sql injection vulnerabilityAn issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggrega…EPSS 0.63%9.8CVE-2024-53908Djangoproject django sql injection vulnerabilityAn issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey…EPSS 1.4%9.8CVE-2023-31047Djangoproject django improper input validation vulnerabilityIn Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multipl…EPSS 1.4%9.8CVE-2022-34265Django Trunc() and Extract() database functions SQL injectionDjango 3.2 before 3.2.14 and 4.0 before 4.0.6 allow SQL injection when untrusted data is passed as the kind or lookup_name argument to the Trunc() an…EPSS 74%analysed9.8CVE-2022-28347Djangoproject django sql injection vulnerabilityA SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passi…EPSS 2.9%9.8CVE-2022-28346Djangoproject django sql injection vulnerabilityAn issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods a…EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2020-7471), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.