PT-2026-56196 · Django+1 · Django+1

·

CVE-2026-53877

·

Published

2026-07-07

·

Updated

2026-08-19

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Django versions 6.0 through 6.0.6 Django versions 5.2 through 5.2.15
Description An issue exists where django.contrib.gis.gdal.GDALRaster over-reads its in-memory buffer when constructed from a bytes object. This can lead to the disclosure of adjacent memory or cause service degradation through a potential segmentation fault—a specific type of error that occurs when a program attempts to access a memory location it is not allowed to access—when the vsi buffer property is accessed.
Recommendations Update Django versions 6.0 through 6.0.6 to version 6.0.7. Update Django versions 5.2 through 5.2.15 to version 5.2.16.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DJANGO-2026-53877
CVE-2026-53877
ECHO-540D-90D3-8A54
GHSA-CRHF-3PFG-W68W
OESA-2026-3074
OESA-2026-3075
OESA-2026-3076
OESA-2026-3077
OESA-2026-3078
OPENSUSE-SU-2026:11235-1
OPENSUSE-SU-2026:11236-1
OPENSUSE-SU-2026:11248-1
OPENSUSE-SU-2026:11270-1
OPENSUSE-SU-2026:21313-1
PYSEC-2026-2091
SUSE-SU-2026:2819-1

Affected Products

Django
Red Os