CVE-2026-15307
Gravedad CVSS v4.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
04/08/2026
Última modificación:
18/08/2026
Descripción
*** Pendiente de traducción *** An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.<br />
GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lookup against a `GeometryField` or `RasterField` reaches this constructor, including untrusted input, for example a spatial-field filter submitted through the Django admin changelist query string by a staff user with view permission. A `dict`, or a `str` holding its JSON representation, is opened in write mode regardless of the constructor&#39;s `write=False` default, allowing a file with an attacker-chosen name and contents to be written through a file-backed GDAL driver. Any other `str` is treated as a datasource, allowing an outbound network request through a GDAL virtual filesystem handler. Writing a file to a location later imported by the application can result in remote code execution.<br />
Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.<br />
Django would like to thank Bence Nagy, localhost-detect, and kimchunbok_ for reporting this issue.
Impacto
Puntuación base 4.0
8.70
Gravedad 4.0
ALTA
Puntuación base 3.x
8.80
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | 5.2.17 (excluyendo) | |
| cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | 6.0 (incluyendo) | 6.0.8 (excluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://docs.djangoproject.com/en/dev/releases/security/
- https://github.com/django/django/commit/115ffd0463a765ab1cc93de18e94b5459b8a300e
- https://github.com/django/django/commit/208f80cb682868b584ed0a78f23e4ba6304212aa
- https://github.com/django/django/commit/39b3e2d0c743a338def6c473086ebc06865e86b6
- https://github.com/django/django/commit/f1949c1f9758947ade984c895ff16bef46f56520
- https://groups.google.com/g/django-announce
- https://www.djangoproject.com/weblog/2026/aug/04/security-releases/


