Executive brief
Django, a popular web framework, contains a vulnerability in its geographic data handling component. An attacker could potentially crash the application or view sensitive information stored in the server's memory. This could lead to service outages or the unauthorized disclosure of internal data.
Technical details
A heap buffer over-read vulnerability (CWE-805) exists in the `django.contrib.gis.gdal.GDALRaster` component of Django. The flaw occurs when a `GDALRaster` object is constructed from a bytes object, causing it to over-read its in-memory buffer. An attacker can trigger this by accessing the `vsi_buffer` property, which may result in the disclosure of adjacent heap memory or a segmentation fault leading to a denial-of-service. The vulnerability is reachable over the network if the application processes user-supplied raster data. Patches are available in versions 5.2.16 and 6.0.7.
Affected products
- Django Software Foundation Django 5.2 before 5.2.16, 6.0 before 6.0.7
Timeline
- 2026-07-07: disclosed
- 2026-07-07: patched
- 2026-07-07: advisory
References
- https://docs.djangoproject.com/en/dev/releases/security
- https://groups.google.com/g/django-announce
- https://www.djangoproject.com/weblog/2026/jul/07/security-releases
- https://github.com/django/django/commit/38dfbd27d7d4f4e6eaa087d7a90f2613fbf55b3a
- https://github.com/django/django/commit/6c66eb8cec52b303af85c2c6e4dd00aa37654dbc