CVE-2026-87890: Potential request forgery via spatial lookup byte values
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply bytes values to cause the Django process to make network requests via a crafted VRT document referencing an external raster source. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank sicksec for reporting this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Djangoto a version that resolves this vulnerability.Fixed in 6.1.2 - Upgrade
Upgrade
Djangoto a version that resolves this vulnerability.Fixed in 6.0.9 - Upgrade
Upgrade
Djangoto a version that resolves this vulnerability.Fixed in 5.2.18
Event History
Frequently Asked Questions
Which deployments are confirmed affected?
Django versions before 6.1.2 in the 6.1 series, before 6.0.9 in the 6.0 series, and before 5.2.18 in the 5.2 series are affected. Unsupported series including 5.1.x, 5.0.x, and 4.2.x were not evaluated and may also be affected.
What must an attacker be able to do to exploit this issue?
An attacker must be able to supply bytes values that reach Django spatial lookups. They can use a crafted VRT document that references an external raster source, causing the Django process to make network requests.
What is the immediate remediation?
Upgrade Django to 6.1.2, 6.0.9, or 5.2.18, as applicable to the supported release series in use. Unsupported Django series were not evaluated, so migration to an evaluated and patched supported series is appropriate.