Skip to main content

Description

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

Severity

CVSS 3.1 · CISA5.4 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
SSVC · CISA-ADP
Exploitationnone
Automatableno
Technical impactpartial

Affected Products

VendorProductAffected versions
djangoprojectDjango
6.0 to <6.0.2
6.0.2 (unaffected)
5.2 to <5.2.11
5.2.11 (unaffected)
4.2 to <4.2.28
4.2.28 (unaffected)

References

3 Links

Record Details

Published
2026-02-03
Last updated
2026-07-15
Assigner (CNA)
DSF
Credited to
Tarek Nakkouch; Jacob Walls; Jacob Walls

Related Tool Categories

Tool categories that test for or protect against this vulnerability class.

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.