All CVEs
Vulnerability intelligence

CVE-2026-1207

djangoproject Django CWE-89

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

CVSS Score
8.3
High
EPSS — Exploit Probability
13%
Riskier than 96% of all CVEs · checked 2026-10-07
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
NVD entry Vendor patch PoC / advisory

2 articles across 1 outlet · first covered Jul 10, 2026 · latest Jul 10, 2026

Coverage timeline

Related CVEs — djangoproject