Sceawere

Vulnerability Detail

CVE-2026-87890UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Django Spatial Lookup SSRF Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
11h ago
Vendor
djangoproject
Product
Django
Attack Type
CWE-918: Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply `bytes` values to cause the Django process to make network requests via a crafted VRT document referencing an external raster source. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank sicksec for reporting this issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-06T14:17:47.380Z",
  "pubdate": "2026-10-06T14:17:47.380Z",
  "executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists within Django's spatial lookup functionality due to an incomplete mitigation of CVE-2026-15307.\nThe vulnerability allows an authenticated or unauthenticated attacker, depending on the application context, to supply specifically crafted 'bytes' values that trigger the underlying GDAL/Raster infrastructure to perform unauthorized network requests.\nBy manipulating the VRT (Virtual Raster) document structure, an attacker can force the Django process to fetch resources from external raster sources, which may lead to internal network scanning, access to cloud metadata services, or data exfiltration.\nAffected versions include Django 6.1 (prior to 6.1.2), 6.0 (prior to 6.0.9), and 5.2 (prior to 5.2.18). Legacy, unsupported branches including 5.1.x, 5.0.x, and 4.2.x are also potentially vulnerable.\nThe primary risk involves the exploitation of the server's network location to interact with internal services or conduct reconnaissance against infrastructure that is otherwise protected by firewalls.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient sanitization of input passed to Django's spatial lookups, which interact with the Geospatial Data Abstraction Library (GDAL). The system fails to properly validate or restrict the contents of 'bytes' objects used within VRT document definitions.\nA VRT file is an XML-based format used by GDAL to describe raster data. Within this format, it is possible to define 'SourceFilename' elements that point to external network locations. When the Django spatial lookup component processes these user-supplied bytes, it improperly passes them to the raster processing engine without adequately restricting the schemes or targets of those references.\nThe attack flow initiates when an attacker injects a malicious VRT payload containing a reference to an external URL (e.g., http://internal-service/ or cloud instance metadata endpoints like http://169.254.169.254/) into a Django spatial query.\nBecause the underlying raster processing utility treats these VRT documents as valid directives for data retrieval, it initiates an outbound HTTP/network request from the Django application process context. This effectively turns the application into an SSRF proxy.\nThe vulnerability is a direct consequence of an incomplete fix for CVE-2026-15307, indicating that the original patch failed to account for all vectors through which 'bytes' could be injected to manipulate the VRT generation process.\nThe impact is significant for applications running in cloud environments, where an attacker can access sensitive instance credentials via the Metadata Service (IMDS). In traditional environments, it allows an attacker to bypass firewalls and interact with internal administrative interfaces or databases that are not exposed to the public internet.\nSince the vulnerability originates in the interaction between Django's high-level spatial ORM and the low-level GDAL implementation, the attack is largely dependent on the application's ability to accept and process spatial data from user-controllable sources. Authentication requirements vary based on the specific application's implementation of spatial data input forms or APIs."
}
CVE-2026-87890: Django Spatial Lookup SSRF Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere