Denial-of-Service Vulnerability in Django's GeoDjango Spatial Features
CVE-2026-15830
6.9MEDIUM
What is CVE-2026-15830?
A denial-of-service vulnerability has been identified in Django's GeoDjango package that affects the GEOSGeometry component. When parsing deeply nested GEOMETRYCOLLECTION objects via well-known text (WKT), well-known binary (WKB), or hex-encoded WKB formats, the system is susceptible to unbounded recursion. This can result in a segmentation fault in the core GEOS library, affecting spatial field lookups and the GeometryField form field in Django applications. Previous unsupported Django versions may also be impacted, underscoring the need for all users to upgrade to the latest secure releases.
Affected Version(s)
Django 6.0 < 6.0.8
Django 5.2 < 5.2.17
Django 6.0.8
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Andrew MacPherson and kimchunbok_
Jacob Walls
Natalia Bidart
