PT-2026-6030 · Django+3 · Django+3

Jacob Walls

+1

·

Published

2026-02-03

·

Updated

2026-05-11

·

CVE-2026-1207

CVSS v4.0

8.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions Django versions prior to 6.0.2 Django versions prior to 5.2.11 Django versions prior to 4.2.28 Django versions 5.0.x and earlier Django versions 4.1.x and earlier Django versions 3.2.x and earlier
Description A SQL injection flaw exists in Django’s GeoDjango RasterField implementation when used with a PostGIS backend. This issue arises from a failure to properly parameterize the raster band index during RasterField lookup processing, allowing attackers to inject arbitrary SQL queries. Attackers can exploit this by crafting malicious input to the raster band parameter. Successful exploitation could lead to arbitrary SQL execution, data theft, modification of data, authentication bypass, potential remote code execution, and disruption of services. The vulnerability affects applications using GeoDjango RasterField with PostGIS and exposing raster lookups via user input.
Recommendations Upgrade to Django version 6.0.2 or later. Upgrade to Django version 5.2.11 or later. Upgrade to Django version 4.2.28 or later. For unsupported Django series (5.0.x, 4.1.x, and 3.2.x), migrate to a supported version. Restrict access to raster endpoints. Deploy WAF rules to filter SQL injection patterns. Enforce strict input validation. Review application and database logs for anomalous raster queries and unexpected PostGIS function usage.

Exploit

Fix

RCE

DoS

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2026-03466
BIT-DJANGO-2026-1207
CVE-2026-1207
ECHO-37CC-2AE7-E3C8
GHSA-MWM9-4648-F68Q
MGASA-2026-0032
OESA-2026-1307
OESA-2026-1308
OESA-2026-1309
OESA-2026-1343
OESA-2026-1344
OESA-2026-1507
OPENSUSE-SU-2026:10145-1
OPENSUSE-SU-2026:10160-1
OPENSUSE-SU-2026:10247-1
OPENSUSE-SU-2026:20184-1
PYSEC-2026-44
RHSA-2026:14835
RHSA-2026:3958
RHSA-2026:3959
RHSA-2026:5970
RHSA-2026:5971
SUSE-SU-2026:0440-1
USN-8009-1

Affected Products

Django
Linuxmint
Red Os
Ubuntu