/Vulnerability Library

Django RasterField - SQL Injection

CVE-2026-1207
Verified

Description

Django < 6.0.2, < 5.2.11, and < 4.2.28 contains a SQL injection caused by improper sanitization of the band index parameter in RasterField on PostGIS, letting remote attackers inject SQL, exploit requires crafted input.

Severity

High

CVSS Score

8.1

Exploit Probability

13%

Affected Product

django

Published Date

February 5, 2026

Template Author

omarkurt

CVE-2026-1207.yaml
8.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVE ID:
cve-2026-1207
CWE ID:
cwe-89

References

https://nvd.nist.gov/vuln/detail/CVE-2026-1207https://www.djangoproject.com/weblog/2026/feb/03/security-releases/https://github.com/django/django/commit/81aa5292967cd09319c45fe2c1a525ce7b6684d8

Remediation Steps

Upgrade to versions 6.0.2, 5.2.11, 4.2.28 or later.