← Back to CVE List
CVE-2026-87890NVD
Vulnerability Summary
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18.
An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply `bytes` values to cause the Django process to make network requests via a crafted VRT document referencing an external raster source.
Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.
Django would like to thank sicksec for reporting this issue.
An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply `bytes` values to cause the Django process to make network requests via a crafted VRT document referencing an external raster source.
Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.
Django would like to thank sicksec for reporting this issue.
CVSS v4.0 Base Metrics — Score 6.9 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)None
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)Low
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 5.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityNone
AvailabilityNone
Affected & Patched Versions
- djangoproject Django >= 6.1 and < 6.1.2
- djangoproject Django >= 6.0 and < 6.0.9
- djangoproject Django >= 5.2 and < 5.2.18
- djangoproject Django 6.1.2
- djangoproject Django 6.0.9
- djangoproject Django 5.2.18
External References
- https://docs.djangoproject.com/en/dev/releases/security/
- https://groups.google.com/g/django-announce
- https://github.com/django/django/commit/ebcb13b327301f28cbc6cd5e4988a719f00575aa
- https://github.com/django/django/commit/4e77ef1e69c94780006b82795aa7db101996c3af
- https://github.com/django/django/commit/a2347fe8234a1831d56c875acc0ea51e0742957c
- https://github.com/django/django/commit/dd0558d1617619e0d66163675ef02135d0f54e5f
- https://www.djangoproject.com/weblog/2026/oct/06/security-releases/