Vulnerability in Django's GeoDjango Spatial Lookups Affecting Multiple Versions
CVE-2026-15307

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-15307?

CVE-2026-15307 is a vulnerability found in Django's GeoDjango spatial lookups, affecting versions prior to 5.2.17 and 6.0.8. GeoDjango is an extension of the Django web framework, designed to facilitate the handling of geographic data in web applications. This vulnerability arises from the way GeoDjango optimistically parses input values used in spatial lookups against GeometryField or RasterField. When untrusted input, such as filtering through Django's admin interface, is processed, it can be passed to the GDALRaster constructor in an insecure manner.

The core issue is that any dictionary or string representation used in these lookups gets processed with incorrect assumptions about the input’s safety, allowing an attacker to write files to arbitrary locations through a GDAL virtual filesystem. Such a breach can lead to remote code execution if an adversary is able to write malicious files that are later utilized by the application. Earlier unsupported Django versions may also be vulnerable, although they have not been specifically evaluated.

Potential impact of CVE-2026-15307

  1. Remote Code Execution: The primary risk associated with this vulnerability is the potential for remote code execution. If attackers can manipulate spatial lookups to write files with customized content and names, they can execute arbitrary code on the server, leading to system compromise and data breaches.

  2. Data Integrity Breach: By exploiting this vulnerability, attackers could alter application behavior or corrupt data, resulting in loss of data integrity. This can adversely affect application performance and the reliability of user data.

  3. Exposure to Further Attacks: A successful exploit may provide attackers with broader access to the environment, allowing them to deploy additional malicious payloads or compromise connected systems, making this vulnerability a launching point for more extensive attacks.

Affected Version(s)

Django 6.0 < 6.0.8

Django 5.2 < 5.2.17

Django 6.0.8

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bence Nagy, localhost-detect, and kimchunbok_
Jacob Walls
Natalia Bidart
.