Django RasterField - SQL Injection
CVE-2026-1207
Verified
Description
Django < 6.0.2, < 5.2.11, and < 4.2.28 contains a SQL injection caused by improper sanitization of the band index parameter in RasterField on PostGIS, letting remote attackers inject SQL, exploit requires crafted input.
Severity
High
CVSS Score
8.1
Exploit Probability
13%
Affected Product
django
Published Date
February 5, 2026
Template Author
omarkurt
CVE-2026-1207.yaml
8.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVE ID:
cve-2026-1207
CWE ID:
cwe-89
Remediation Steps
Upgrade to versions 6.0.2, 5.2.11, 4.2.28 or later.