Django < 6.0.2, < 5.2.11, and < 4.2.28 contains a SQL injection caused by improper sanitization of the band index parameter in RasterField on PostGIS, letting remote attackers inject SQL, exploit requires crafted input.
id: CVE-2026-1207
info:
name: Django RasterField - SQL Injection
author: omarkurt
severity: h
...