6.9
CVE-2026-87890
- EPSS 0.29%
- Veröffentlicht 06.10.2026 13:35:37
- Zuletzt bearbeitet 06.10.2026 14:17:47
- Erkennungen
Potential request forgery via spatial lookup byte values
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply `bytes` values to cause the Django process to make network requests via a crafted VRT document referencing an external raster source. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank sicksec for reporting this issue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerdjangoproject
≫
Produkt
Django
Default Statusunaffected
Version
6.1
Version <
6.1.2
Status
affected
Version
6.1.2
Status
unaffected
Version
6.0
Version <
6.0.9
Status
affected
Version
6.0.9
Status
unaffected
Version
5.2
Version <
5.2.18
Status
affected
Version
5.2.18
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.194 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 | 6.9 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://docs.djangoproject.com/en/dev/releases/security/
https://groups.google.com/g/django-announce
https://www.djangoproject.com/weblog/2026/oct/06/security-releases/
https://github.com/django/django/commit/ebcb13b327301f28cbc6cd5e4988a719f00575aa
https://github.com/django/django/commit/4e77ef1e69c94780006b82795aa7db101996c3af
https://github.com/django/django/commit/a2347fe8234a1831d56c875acc0ea51e0742957c
https://github.com/django/django/commit/dd0558d1617619e0d66163675ef02135d0f54e5f