Network Request Vulnerability in Django Framework Affects Multiple Versions
CVE-2026-87890

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-87890?

An issue has been identified in the Django framework where an incomplete fix for a prior vulnerability related to spatial lookups facilitates unauthorized network requests. This issue, which affects multiple versions of Django including 6.1, 6.0, and 5.2, allows attackers to exploit the framework by supplying crafted bytes values through a VRT document linked to an external raster source. Unsupported versions such as 5.1.x, 5.0.x, and 4.2.x may also be impacted, thus broadening the potential attack surface. Users are urged to apply the latest security patches provided by the Django project.

Affected Version(s)

Django 6.1 < 6.1.2

Django 6.0 < 6.0.9

Django 5.2 < 5.2.18

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sicksec
Sarah Boyce
Sarah Boyce
.