CVE-2026-15307

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
04/08/2026
Last modified:
18/08/2026

Description

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.<br /> GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lookup against a `GeometryField` or `RasterField` reaches this constructor, including untrusted input, for example a spatial-field filter submitted through the Django admin changelist query string by a staff user with view permission. A `dict`, or a `str` holding its JSON representation, is opened in write mode regardless of the constructor&amp;#39;s `write=False` default, allowing a file with an attacker-chosen name and contents to be written through a file-backed GDAL driver. Any other `str` is treated as a datasource, allowing an outbound network request through a GDAL virtual filesystem handler. Writing a file to a location later imported by the application can result in remote code execution.<br /> Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.<br /> Django would like to thank Bence Nagy, localhost-detect, and kimchunbok_ for reporting this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* 5.2.17 (excluding)
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* 6.0 (including) 6.0.8 (excluding)