Medium severity5.4OSV Advisory· Published Feb 3, 2026· Updated Jul 15, 2026
CVE-2026-1207
CVE-2026-1207
Description
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on `RasterField` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
DjangoPyPI | >= 6.0a1, < 6.0.2 | 6.0.2 |
DjangoPyPI | >= 5.2a1, < 5.2.11 | 5.2.11 |
DjangoPyPI | >= 4.2a1, < 4.2.28 | 4.2.28 |
Affected products
154.2, 4.2.1, 4.2.10, …+ 1 more
- (no CPE)range: 4.2, 4.2.1, 4.2.10, …
- cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*range: >=4.2,<4.2.28
- osv-coords13 versionspkg:apk/chainguard/authentikpkg:apk/chainguard/authentik-fipspkg:apk/chainguard/awxpkg:apk/chainguard/label-studiopkg:bitnami/djangopkg:pypi/djangopkg:rpm/opensuse/python-Django&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python-Django&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python-Django&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django4&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django5&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django6&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-Django&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7
< 2025.12.1-r2+ 12 more
- (no CPE)range: < 2025.12.1-r2
- (no CPE)range: < 2025.12.1-r2
- (no CPE)range: < 24.6.1-r27
- (no CPE)range: < 1.22.0-r3
- (no CPE)range: >= 4.2.0, < 4.2.28
- (no CPE)range: >= 6.0a1, < 6.0.2
- (no CPE)range: < 4.2.11-150600.3.47.1
- (no CPE)range: < 5.2.4-bp160.5.1
- (no CPE)range: < 5.2.11-1.1
- (no CPE)range: < 4.2.28-1.1
- (no CPE)range: < 5.2.16-1.1
- (no CPE)range: < 6.0.2-1.1
- (no CPE)range: < 4.2.11-150600.3.47.1
Patches
Vulnerability mechanics
References
21- docs.djangoproject.com/en/dev/releases/security/nvdPatchVendor Advisory
- www.djangoproject.com/weblog/2026/feb/03/security-releases/nvdPatchVendor Advisory
- github.com/advisories/GHSA-mwm9-4648-f68qghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-1207ghsaADVISORY
- docs.djangoproject.com/en/dev/releases/securityghsaWEB
- github.com/django/django/commit/81aa5292967cd09319c45fe2c1a525ce7b6684d8ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2026-44.yamlghsaWEB
- groups.google.com/g/django-announcenvdRelease NotesWEB
- www.djangoproject.com/weblog/2026/feb/03/security-releasesghsaWEB
- access.redhat.com/errata/RHSA-2026:14835nvd
- access.redhat.com/errata/RHSA-2026:2694nvd
- access.redhat.com/errata/RHSA-2026:3958nvd
- access.redhat.com/errata/RHSA-2026:3959nvd
- access.redhat.com/errata/RHSA-2026:3960nvd
- access.redhat.com/errata/RHSA-2026:3962nvd
- access.redhat.com/errata/RHSA-2026:5970nvd
- access.redhat.com/errata/RHSA-2026:5971nvd
- access.redhat.com/errata/RHSA-2026:6291nvd
- access.redhat.com/security/cve/CVE-2026-1207nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1207.jsonnvd
News mentions
4- Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant BugThe Hacker News · Aug 5, 2026
- ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and MoreThe Hacker News · Jul 13, 2026
- Cyber Security Newsletter and Bulletin Weekly – 16-Year-Old Linux, Ubiquiti Flaws, Accenture Breach, Android 17 Exploit +20 StoriesCyber Security News · Jul 12, 2026
- Django SQL Injection Vulnerability Actively Exploited in the WildCyber Security News · Jul 10, 2026