{"id":"CVE-2026-15830","aliases":["PYSEC-2026-3717","BIT-django-2026-15830"],"title":"An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.","summary":"An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.\nGeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as …","severity":"none","vendor":"django","product":"django","ecosystem":"pip","affected":["django >= 6.0, < 6.0.8"],"patched":["django 6.0.8"],"published":"2026-08-04","updated":"2026-08-19","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/PYSEC-2026-3717","references":[{"url":"https://www.djangoproject.com/weblog/2026/aug/04/security-releases/"},{"url":"https://docs.djangoproject.com/en/dev/releases/security/"},{"url":"https://github.com/django/django/commit/6af5da31775417c610dbf9c3f1b5b8333d42daf6"},{"url":"https://github.com/django/django/commit/9e4a3f186b6b07b483bfd9195ea06734663fcd06"},{"url":"https://github.com/django/django/commit/ba80833fa656dd09660b97c4429331067db1b080"},{"url":"https://github.com/django/django/commit/d2e59b77fe18de318a8272c2a7bbc798d84d1d0d"},{"url":"https://groups.google.com/g/django-announce"}],"tags":["osv","pip"],"epss":0.00763,"epssPercentile":0.53403,"ingestedAt":"2026-08-19T19:22:21.743Z","slug":"CVE-2026-15830","body":"## Overview\n\nAn issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.\nGeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected.\nEarlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.\nDjango would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue.\n\n## Affected packages\n\n- `django >= 6.0, < 6.0.8`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `django 6.0.8`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}