Vulnerability record · CVE-2022-34265 · published 4 July 2022
CVE-2022-34265: Django Trunc() and Extract() database functions SQL injection
Djangoproject · Django
Django 3.2 before 3.2.14 and 4.0 before 4.0.6 allow SQL injection when untrusted data is passed as the kind or lookup_name argument to the Trunc() and Extract() database functions. Applications that restrict these values to a fixed safe list are not affected. Because the flaw is in a core database function, any code path that forwards user input into these arguments can expose the database.
Description
An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCritical CVSS 9.8 and very high EPSS, but exploitation requires the application to pass untrusted data into the affected arguments, so exposure is conditional.
What it is
Django 3.2 before 3.2.14 and 4.0 before 4.0.6 allow SQL injection when untrusted data is passed as the kind or lookup_name argument to the Trunc() and Extract() database functions. Applications that restrict these values to a fixed safe list are not affected. Because the flaw is in a core database function, any code path that forwards user input into these arguments can expose the database.
Impact
An attacker can inject arbitrary SQL through the kind or lookup_name parameter, potentially reading, modifying or deleting database contents and, depending on database privileges, executing database-level operations.
Attack surface
Reached over the network through any application endpoint that passes user-controlled input into Trunc() or Extract() kind or lookup_name values. The CVSS vector indicates no authentication and no user interaction are required, though real exposure depends on whether the application forwards untrusted data to these arguments.
Exploitation
Not listed in CISA KEV, but EPSS is very high at roughly 0.73 probability over 30 days (99.4th percentile), indicating elevated likelihood of exploitation activity. References are patch and advisory only, with no public exploit tag supplied.
What to do
- Upgrade Django to 3.2.14 or 4.0.6 or later; apply the vendor security release immediately.
- If immediate upgrade is not possible, restrict kind and lookup_name values to a hardcoded allowlist and never pass raw user input.
- Audit application code for calls to Trunc() and Extract() that accept request data and refactor them to use fixed values.
- Update downstream packages and distributions (Fedora, Debian, NetApp products) to versions carrying the patched Django.
- Run the database account used by the application with least privilege to limit injection impact.
Detection
- Search application and dependency manifests for Django versions below 3.2.14 or 4.0.6.
- Grep source code for Trunc( and Extract( calls where kind or lookup_name derives from request parameters.
- Monitor database logs for anomalous SQL patterns or errors originating from ORM-generated queries.
- Review web logs for requests targeting endpoints that build date or time truncation lookups from user input.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-34265 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-34265), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.