Django django是Django基金会开源的一个Web应用开发框架。 Django 5.2.17版本之前的5.2.x版本和6.0.8版本之前的6.0.x版本存在资源管理错误漏洞,该漏洞源于GeoDjango的GEOSGeometry在解析以WKT、WKB或十六进制编码WKB提供的深层嵌套GEOMETRYCOLLECTION对象时存在无限递归,可能导致底层GEOS库发生分段错误,从而引发拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| djangoproject | Django | 6.0< 6.0.8 |
affected |
6.0.8 |
unaffected | ||
5.2< 5.2.17 |
affected | ||
5.2.17 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| djangoproject | Django | 6.0 ~ 6.0.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15307 | 8.8 HIGH | Server-side file-write and request forgery via spatial lookups |
| CVE-2026-15920 | 6.1 MEDIUM | Potential cross-site scripting via URLField values in the admin |
| CVE-2026-15337 | 5.3 MEDIUM | Potential denial-of-service vulnerability in check_for_language() |
No comments yet