Network Request Vulnerability in Django Framework Affects Multiple Versions
CVE-2026-87890
6.9MEDIUM
What is CVE-2026-87890?
An issue has been identified in the Django framework where an incomplete fix for a prior vulnerability related to spatial lookups facilitates unauthorized network requests. This issue, which affects multiple versions of Django including 6.1, 6.0, and 5.2, allows attackers to exploit the framework by supplying crafted bytes values through a VRT document linked to an external raster source. Unsupported versions such as 5.1.x, 5.0.x, and 4.2.x may also be impacted, thus broadening the potential attack surface. Users are urged to apply the latest security patches provided by the Django project.
Affected Version(s)
Django 6.1 < 6.1.2
Django 6.0 < 6.0.9
Django 5.2 < 5.2.18
