---
title: "Django 4.0.4 release notes"
version: 5.1
locale: fr
source: https://docs.djangoproject.com/fr/5.1/releases/4.0.4/
canonical: https://djangodocs.dev/fr/5.1/releases/4.0.4/
---
# Django 4.0.4 release notes

*April 11, 2022*

Django 4.0.4 fixes two security issues with severity « high » and two bugs in
4.0.3.

## CVE-2022-28346: Potential SQL injection in `QuerySet.annotate()`, `aggregate()`, and `extra()`

[`QuerySet.annotate()`](/fr/5.1/ref/models/querysets/#django.db.models.query.QuerySet.annotate), [`aggregate()`](/fr/5.1/ref/models/querysets/#django.db.models.query.QuerySet.aggregate), and
[`extra()`](/fr/5.1/ref/models/querysets/#django.db.models.query.QuerySet.extra) methods were subject to SQL injection in column
aliases, using a suitably crafted dictionary, with dictionary expansion, as the
`**kwargs` passed to these methods.

## CVE-2022-28347: Potential SQL injection via `QuerySet.explain(**options)` on PostgreSQL

[`QuerySet.explain()`](/fr/5.1/ref/models/querysets/#django.db.models.query.QuerySet.explain) method was subject to SQL injection in option names,
using a suitably crafted dictionary, with dictionary expansion, as the
`**options` argument.

## Correction de bogues

- Fixed a regression in Django 4.0 that caused ignoring multiple
  `FilteredRelation()` relationships to the same field ([#33598](https://code.djangoproject.com/ticket/33598)).
- Fixed a regression in Django 3.2.4 that caused the auto-reloader to no longer
  detect changes when the `DIRS` option of the `TEMPLATES` setting
  contained an empty string ([#33628](https://code.djangoproject.com/ticket/33628)).
