The Django project released Django 6.0.8 and Django 5.2.17 to fix four vulnerabilities, led by CVE-2026-15307, a high-severity flaw in GeoDjango spatial lookups. The bug affects cases where untrusted str or dict input is passed to django.contrib.gis.gdal.GDALRaster, allowing attacker-controlled server-side file writes and outbound requests through GDAL virtual filesystem handlers; in some deployments, that file-write primitive can be chained into remote code execution if the written file is later imported by the application. Reports said the issue could be exploited remotely with low privileges, including by a staff user through a Django admin changelist query string.
The same releases also addressed CVE-2026-15337, a low-severity denial-of-service issue in check_for_language(); CVE-2026-15830, a moderate denial-of-service flaw triggered by deeply nested GEOMETRYCOLLECTION objects in GEOSGeometry; and CVE-2026-15920, a moderate stored cross-site scripting issue in Django admin rendering of URLField values. Supported branches including Django main, the 6.1 release candidate, 6.0, and 5.2 received fixes, and the project urged users to upgrade promptly; older unsupported branches such as 5.1.x, 5.0.x, and 4.2.x were not evaluated and may also be affected.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
On August 4, 2026, Django patched CVE-2026-15920, a moderate-severity cross-site scripting issue in the admin where URLField values could be rendered as clickable links without safe-scheme validation. The fix added URLValidator checks in display_for_field() and now falls back to plain-text rendering for unsafe values such as javascript: or data: URLs.
On August 4, 2026, Django disclosed and patched CVE-2026-15830, a denial-of-service issue in geographic geometry processing where deeply nested GEOMETRYCOLLECTION input could trigger a segmentation fault in GEOS. The fix capped nested geometry collections at 198 for WKT and WKB input and added a max_geom_collections setting for GEOSGeometry and related fields.
On August 4, 2026, Django committed fix 224dbc8 for CVE-2026-15337 on the stable/6.0.x branch and shipped it in Django 6.0.8. The patch mitigated the potential denial-of-service issue in check_for_language() by rejecting language codes longer than 500 characters before cached lookup and moving catalog existence checks into a separate cached helper.
On August 4, 2026, Django fixed CVE-2026-15337 in commit c72a5db and shipped it in Django 5.2.17. The low-severity flaw in django.utils.translation.check_for_language() could allow attacker-controlled long language codes to accumulate as cache keys and consume memory, so Django began rejecting codes longer than 500 characters before cached lookup.
On August 4, 2026, CVE-2026-15307 was published for a high-severity GeoDjango issue in which untrusted spatial lookup input could trigger server-side file writes, outbound network requests, and in some cases remote code execution. The issue affects Django 5.2 before 5.2.17 and 6.0 before 6.0.8, and Django credited Bence Nagy, localhost-detect, and kimchunbok_ for reporting it.
On August 4, 2026, the Django team issued security releases Django 6.0.8 and Django 5.2.17. The releases fixed CVE-2026-15307, CVE-2026-15337, CVE-2026-15830, and CVE-2026-15920 across supported branches.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
17 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcesecurity-tracker.debian.org
Open sourcedocs.djangoproject.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.