CVE-2026-87890

Source
https://cve.org/CVERecord?id=CVE-2026-87890
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87890.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-87890
Downstream
Published
2026-10-06T13:35:37Z
Modified
2026-10-08T02:48:34Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N CVSS Calculator
Summary
Potential request forgery via spatial lookup byte values
Details

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply bytes values to cause the Django process to make network requests via a crafted VRT document referencing an external raster source. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank sicksec for reporting this issue.

Database specific
{
    "cna_assigner": "DSF",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87890.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "6.1"
                },
                {
                    "fixed": "6.1.2"
                },
                {
                    "introduced": "6.0"
                },
                {
                    "fixed": "6.0.9"
                },
                {
                    "introduced": "5.2"
                },
                {
                    "fixed": "5.2.18"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "6.1"
                },
                {
                    "fixed": "6.1.2"
                },
                {
                    "introduced": "6.0"
                },
                {
                    "fixed": "6.0.9"
                },
                {
                    "introduced": "5.2"
                },
                {
                    "fixed": "5.2.18"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/django/django

Affected ranges

Type
GIT
Repo
https://github.com/django/django
Events
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

1.*
1.0
1.1
1.2
1.2.1
1.3
1.4
1.7a2
5.*
5.2
5.2.1
5.2.10
5.2.11
5.2.12
5.2.13
5.2.14
5.2.15
5.2.16
5.2.17
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8
5.2.9
5.2a1
5.2b1
5.2rc1
6.*
6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0a1
6.0b1
6.0rc1
6.1
6.1.1
6.1a1
6.1b1
6.1rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87890.json"