What is CVE-2026-15830?
A vulnerability was found in Django's GeoDjango module, where parsing deeply nested `GEOMETRYCOLLECTION` objects via `GEOSGeometry` in WKT, WKB, or hex formats can lead to a denial-of-service. Versions before 5.2.17 and 6.0.8 are affected, and an immediate update is recommended.
Azərbaycanca: Bu boşluq Django-nun GeoDjango modulunda aşkarlanıb. Xüsusi olaraq, dərin iç-içə `GEOMETRYCOLLECTION` obyektlərini WKT, WKB və ya hex formatında emal edərkən `GEOSGeometry` funksiyası vasitəsilə denial-of-service (DoS) hücumuna səbəb ola bilər. Django 5.2.17 və 6.0.8 versiyalarından əvvəlki versiyalar təsirlənir, dərhal yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What Django versions are affected by CVE-2026-15830?
This vulnerability affects Django versions before 5.2.17 and 6.0.8.
In what formats can CVE-2026-15830 trigger a denial-of-service (DoS) attack?
The vulnerability can lead to a denial-of-service (DoS) when parsing in WKT, WKB, or hex formats.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.