๐Ÿ” CVE Alert

CVE-2026-87890

MEDIUM 5.3

Potential request forgery via spatial lookup byte values

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply `bytes` values to cause the Django process to make network requests via a crafted VRT document referencing an external raster source. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank sicksec for reporting this issue.

CWE CWE-918
Vendor djangoproject
Product django
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for djangoproject django

Be the first to know when new medium vulnerabilities affecting djangoproject django are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

djangoproject / Django
6.1 < 6.1.2 6.0 < 6.0.9 5.2 < 5.2.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.djangoproject.com: https://docs.djangoproject.com/en/dev/releases/security/ groups.google.com: https://groups.google.com/g/django-announce github.com: https://github.com/django/django/commit/ebcb13b327301f28cbc6cd5e4988a719f00575aa github.com: https://github.com/django/django/commit/4e77ef1e69c94780006b82795aa7db101996c3af github.com: https://github.com/django/django/commit/a2347fe8234a1831d56c875acc0ea51e0742957c github.com: https://github.com/django/django/commit/dd0558d1617619e0d66163675ef02135d0f54e5f djangoproject.com: https://www.djangoproject.com/weblog/2026/oct/06/security-releases/

Credits

๐Ÿ” sicksec Sarah Boyce Sarah Boyce