← Vulnerability feed

Vulnerability record · CVE-2022-34265 · published 4 July 2022

CVE-2022-34265: Django Trunc() and Extract() database functions SQL injection

Djangoproject · Django

Django 3.2 before 3.2.14 and 4.0 before 4.0.6 allow SQL injection when untrusted data is passed as the kind or lookup_name argument to the Trunc() and Extract() database functions. Applications that restrict these values to a fixed safe list are not affected. Because the flaw is in a core database function, any code path that forwards user input into these arguments can expose the database.

9.8 CVSS 3.1 Critical EPSS 74% · top 0.5% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCritical CVSS 9.8 and very high EPSS, but exploitation requires the application to pass untrusted data into the affected arguments, so exposure is conditional.

What it is

Django 3.2 before 3.2.14 and 4.0 before 4.0.6 allow SQL injection when untrusted data is passed as the kind or lookup_name argument to the Trunc() and Extract() database functions. Applications that restrict these values to a fixed safe list are not affected. Because the flaw is in a core database function, any code path that forwards user input into these arguments can expose the database.

Impact

An attacker can inject arbitrary SQL through the kind or lookup_name parameter, potentially reading, modifying or deleting database contents and, depending on database privileges, executing database-level operations.

Attack surface

Reached over the network through any application endpoint that passes user-controlled input into Trunc() or Extract() kind or lookup_name values. The CVSS vector indicates no authentication and no user interaction are required, though real exposure depends on whether the application forwards untrusted data to these arguments.

Exploitation

Not listed in CISA KEV, but EPSS is very high at roughly 0.73 probability over 30 days (99.4th percentile), indicating elevated likelihood of exploitation activity. References are patch and advisory only, with no public exploit tag supplied.

What to do

  • Upgrade Django to 3.2.14 or 4.0.6 or later; apply the vendor security release immediately.
  • If immediate upgrade is not possible, restrict kind and lookup_name values to a hardcoded allowlist and never pass raw user input.
  • Audit application code for calls to Trunc() and Extract() that accept request data and refactor them to use fixed values.
  • Update downstream packages and distributions (Fedora, Debian, NetApp products) to versions carrying the patched Django.
  • Run the database account used by the application with least privilege to limit injection impact.

Detection

  • Search application and dependency manifests for Django versions below 3.2.14 or 4.0.6.
  • Grep source code for Trunc( and Extract( calls where kind or lookup_name derives from request parameters.
  • Monitor database logs for anomalous SQL patterns or errors originating from ORM-generated queries.
  • Review web logs for requests targeting endpoints that build date or time truncation lookups from user input.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-34265 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-0474Canonical ubuntu linux vulnerabilityThe (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x befor…EPSS 4.9%9.8CVE-2026-4277Djangoproject django missing authorization vulnerabilityAn issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated o…EPSS 0.60%9.8CVE-2025-59681Djangoproject django sql injection vulnerabilityAn issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggrega…EPSS 0.63%9.8CVE-2024-53908Djangoproject django sql injection vulnerabilityAn issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey…EPSS 1.4%9.8CVE-2023-31047Djangoproject django improper input validation vulnerabilityIn Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multipl…EPSS 1.4%9.8CVE-2022-28347Djangoproject django sql injection vulnerabilityA SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passi…EPSS 2.9%9.8CVE-2022-28346Djangoproject django sql injection vulnerabilityAn issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods a…EPSS 19%9.8CVE-2021-35042Djangoproject django sql injection vulnerabilityDjango 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web applic…EPSS 44%

Source: NIST National Vulnerability Database (record CVE-2022-34265), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.