CVE-2026-1207

unknown
Published 2026-02-03 Β· Modified 2026-05-20
CVSS v3
β€”
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
β€”

Description

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

Predictions

Exploit likelihood
30%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker Β· View original β†— Β· DFSG

CVE-2026-1207 NameCVE-2026-1207 DescriptionAn issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to…

CVE-2026-1207

NameCVE-2026-1207
DescriptionAn issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4484-1, DSA-6150-1
Debian Bugs1126914

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python-django (PTS)bullseye2:2.2.28-1~deb11u2vulnerable
bullseye (security)2:2.2.28-1~deb11u12fixed
bookworm, bookworm (security)3:3.2.25-0+deb12u2fixed
trixie (security), trixie3:4.2.28-0+deb13u1fixed
forky3:4.2.30-1fixed
sid3:5.2.15-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python-djangosourcebullseye2:2.2.28-1~deb11u12DLA-4484-1
python-djangosourcebookworm3:3.2.25-0+deb12u2DSA-6150-1
python-djangosourcetrixie3:4.2.28-0+deb13u1DSA-6150-1
python-djangosource(unstable)3:4.2.28-11126914

Notes

https://www.djangoproject.com/weblog/2026/feb/03/security-releases/
Fixed by: https://github.com/django/django/commit/a14363102d98fa29b8cced578eb3a0fadaa5bcb7 (4.2.28)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://www.djangoproject.com/weblog/2026/feb/03/security-releases/Fixed by: https://github.com/django/django/commit/a14363102d98fa29b8cced578eb3a0fadaa5bcb7 (4.2.28)

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 3:4.2.28-0+deb13u1
sid Fixed 3:4.2.28-1
forky Fixed 3:4.2.28-1
bullseye Fixed 2:2.2.28-1~deb11u12
bookworm Fixed 3:3.2.25-0+deb12u2

Package impact

EcosystemPackageVulnerableFixed
python PyPIdjango>=6.0a1,<6.0.26.0.2
python PyPIdjango>=5.2a1,<5.2.115.2.11
python PyPIdjango>=4.2a1,<4.2.284.2.28
python PyPIdjango>=6.0,<6.0.24.2.28

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.