Denial-of-Service Vulnerability in Django's GeoDjango Spatial Features
CVE-2026-15830

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-15830?

A denial-of-service vulnerability has been identified in Django's GeoDjango package that affects the GEOSGeometry component. When parsing deeply nested GEOMETRYCOLLECTION objects via well-known text (WKT), well-known binary (WKB), or hex-encoded WKB formats, the system is susceptible to unbounded recursion. This can result in a segmentation fault in the core GEOS library, affecting spatial field lookups and the GeometryField form field in Django applications. Previous unsupported Django versions may also be impacted, underscoring the need for all users to upgrade to the latest secure releases.

Affected Version(s)

Django 6.0 < 6.0.8

Django 5.2 < 5.2.17

Django 6.0.8

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew MacPherson and kimchunbok_
Jacob Walls
Natalia Bidart
.