在 Django 6.1(6.1.2 版本之前)、6.0(6.0.9 版本之前)以及 5.2(5.2.18 版本之前)版本中,发现了一个漏洞。 该漏洞是 CVE-2026-15307 针对 Django 空间查找功能的不完整修复。攻击者如果能够提供 类型的值,即可通过构造包含外部栅格数据源引用的 VRT 文档,诱使 Django 进程发起网络请求。 此前,不受支持的 Django 系列(例如 5.1.x、5.0.x 和 4.2.x)未被进行评估,但也可能受到该问题的影响。 Django 项目感谢 sicksec 报
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| djangoproject | Django | 6.1 ~ 6.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77050 | 5.3 MEDIUM | Potential denial-of-service vulnerability in get_supported_language_variant() |
| CVE-2026-84429 | 5.3 MEDIUM | Potential denial-of-service vulnerability in HTTP header parsing |
| CVE-2026-87975 | 4.3 MEDIUM | Privilege abuse in model formsets with editable primary keys |
No comments yet