CVE-2026-1207
Potential SQL injection via raster lookups on PostGIS
Description
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NAffected Products
| Vendor | Product | Affected versions |
|---|---|---|
| djangoproject | Django | 6.0 to <6.0.2 6.0.2 (unaffected) 5.2 to <5.2.11 5.2.11 (unaffected) 4.2 to <4.2.28 4.2.28 (unaffected) |
References
3 LinksRecord Details
Related Tool Categories
Tool categories that test for or protect against this vulnerability class.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.