PT-2026-6030 · Django+3 · Django+3

·

CVE-2026-1207

·

Published

2026-02-03

·

Updated

2026-07-14

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Django versions prior to 6.0.2 Django versions prior to 5.2.11 Django versions prior to 4.2.28
Description A flaw in the GeoDjango RasterField implementation, specifically when using a PostGIS backend, allows remote attackers to perform SQL injection. The issue occurs because the software fails to properly parameterize the band index during raster lookup processing, allowing user-supplied input to be concatenated directly into SQL queries. This can lead to unauthorized information disclosure, data alteration, denial of service, or potential remote code execution on database hosts. Real-world incidents indicate that this issue has been actively exploited in targeted attacks against mapping platforms, location services, and geospatial analytics applications. The vulnerability is triggered via the band index parameter during raster lookups.
Recommendations Update Django to version 6.0.2. Update Django to version 5.2.11. Update Django to version 4.2.28. Restrict access to raster endpoints to minimize the risk of exploitation. Enforce strict input validation on the band index parameter. Deploy WAF rules to filter common SQL injection patterns.

Exploit

Fix

RCE

DoS

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03466
BIT-DJANGO-2026-1207
CVE-2026-1207
ECHO-37CC-2AE7-E3C8
GHSA-MWM9-4648-F68Q
MGASA-2026-0032
OESA-2026-1307
OESA-2026-1308
OESA-2026-1309
OESA-2026-1343
OESA-2026-1344
OESA-2026-1507
OPENSUSE-SU-2026:10145-1
OPENSUSE-SU-2026:10160-1
OPENSUSE-SU-2026:10247-1
OPENSUSE-SU-2026:11270-1
OPENSUSE-SU-2026:20184-1
PYSEC-2026-44
RHSA-2026:14835
RHSA-2026:3958
RHSA-2026:3959
RHSA-2026:5970
RHSA-2026:5971
SUSE-SU-2026:0440-1
USN-8009-1

Affected Products

Django
Linuxmint
Red Os
Ubuntu