---
id: CVE-2026-87890
title: >-
  An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2
  before 5.2.18.

  An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an
  attacker who can supply `bytes` values to cause the Django process to m…
summary: >-
  An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2
  before 5.2.18.

  An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an
  attacker who can supply `bytes` values to cause the Django process to m…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-918
vendor: djangoproject
product: django
affected:
  - django >= 6.1 < 6.1.2
  - django >= 6.0 < 6.0.9
  - django >= 5.2 < 5.2.18
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T14:17:47.517'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87890'
references:
  - url: 'https://docs.djangoproject.com/en/dev/releases/security/'
    label: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
  - url: >-
      https://github.com/django/django/commit/4e77ef1e69c94780006b82795aa7db101996c3af
    label: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
  - url: >-
      https://github.com/django/django/commit/a2347fe8234a1831d56c875acc0ea51e0742957c
    label: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
  - url: >-
      https://github.com/django/django/commit/dd0558d1617619e0d66163675ef02135d0f54e5f
    label: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
  - url: >-
      https://github.com/django/django/commit/ebcb13b327301f28cbc6cd5e4988a719f00575aa
    label: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
  - url: 'https://groups.google.com/g/django-announce'
    label: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
  - url: 'https://www.djangoproject.com/weblog/2026/oct/06/security-releases/'
    label: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-06T14:06:27.700001Z'
ingestedAt: '2026-10-06T14:00:19.151Z'
---

## Overview

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18.
An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply `bytes` values to cause the Django process to make network requests via a crafted VRT document referencing an external raster source.
Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.
Django would like to thank sicksec for reporting this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
