CVE-2026-15307 | Django Software Foundation up to 5.2.16/6.0.7 Spatial Lookup gdal.py django.contrib.gis.gdal.GDALRaster.__init__ right-hand-side unrestricted upload

SecurityVulns

A vulnerability has been found in Django Software Foundation Django up to 5.2.16/6.0.7 and classified as critical. This affects the function django.contrib.gis.gdal.GDALRaster.__init__ of the file django/contrib/gis/gdal/gdal.py of the component Spatial Lookup. The manipulation of the argument right-hand-side leads to unrestricted upload.

This vulnerability is documented as CVE-2026-15307. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More