What is CVE-2026-15307?
CVE-2026-15307 is a vulnerability found in Django versions 5.2 prior to 5.2.17 and 6.0 prior to 6.0.8, where GeoDjango spatial lookups optimistically parse the right-hand-side value as a GDALRaster, which could lead to unexpected behavior. Users should immediately upgrade to the patched versions, 5.2.17 or 6.0.8.
Azərbaycanca: CVE-2026-15307, Django 5.2 (5.2.17 öncəsi) və 6.0 (6.0.8 öncəsi) versiyalarında GeoDjango spatial lookup əməliyyatlarında aşkarlanmış bir zəiflikdir. Təhlükəsizlik problemi, `GeometryField` və ya `RasterField` üzərində aparılan sorğularda sağ tərəf dəyərinin optimist şəkildə GDALRaster obyekti kimi parse edilməsindən qaynaqlanır, bu da potensial olaraq gözlənilməz davranışlara yol aça bilər. İstifadəçilərə dərhal Django-nun 5.2.17 və ya 6.0.8 versiyalarına yeniləmə tövsiyə olunur.
FAQ2
Which Django versions are affected by CVE-2026-15307?
CVE-2026-15307 affects Django versions 5.2 prior to 5.2.17 and 6.0 prior to 6.0.8.
What is the cause of vulnerability CVE-2026-15307?
The vulnerability arises from GeoDjango's spatial lookups optimistically parsing the right-hand-side value as a GDALRaster in queries on `GeometryField` or `RasterField`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.