
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-15307 is a server-side file-write and Server-Side Request Forgery (SSRF) vulnerability in Django's GeoDjango component, officially titled "Server-side file-write and request forgery via spatial lookups." It affects Django 5.2 before 5.2.17 and 6.0 before 6.0.8; earlier unsupported series (5.1.x, 5.0.x, 4.2.x) were not evaluated but may also be affected. The vulnerability was disclosed on August 4, 2026, and was reported by Bence Nagy, localhost-detect, and kimchunbok_. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 8.7 (High) (Red Hat Advisory, Django Security Releases).
The root cause is improper input validation in GeoDjango's spatial lookup processing, classified under CWE-73 (External Control of File Name or Path), CWE-918 (SSRF), and CWE-434 (Unrestricted Upload of File with Dangerous Type). When a spatial lookup is performed against a GeometryField or RasterField, the right-hand-side value is optimistically passed to the django.contrib.gis.gdal.GDALRaster constructor before being retried as a geometry. A dict or a JSON-encoded str is opened in write mode by GDAL regardless of the constructor's write=False default, allowing an attacker to write a file with arbitrary name and contents via a file-backed GDAL driver. Any other str is treated as a datasource path, enabling outbound network requests through GDAL virtual filesystem handlers (e.g., /vsicurl/). The attack surface includes the Django admin changelist, which allows staff users with only view permission to submit arbitrary spatial-field filter values via the query string (Django Commit f1949c1, Red Hat Bugzilla).
Successful exploitation allows a low-privileged staff user (view permission only) to write files with attacker-controlled names and contents to the server's filesystem, or to trigger outbound network requests as the Django process user. If a written file is placed in a location subsequently imported by the application (e.g., a Python module path), this can escalate to full remote code execution, compromising confidentiality, integrity, and availability of the affected system. The SSRF vector additionally enables internal network reconnaissance and potential access to cloud metadata services (Django Security Releases, Red Hat Bugzilla).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at the time of disclosure (Feedly). The EPSS score is approximately 0.54%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a low-privilege authenticated account (staff user with view permission), making it less trivially exploitable than unauthenticated vulnerabilities, but the potential for RCE makes it high priority for patching.
GeometryField or RasterField.{"name": "/path/to/writable/malicious.py", "driver": "GTiff", ...} encoded as a JSON string or dict.GET /admin/app/model/?spatial_field=<payload>. The value reaches GDALRaster constructor and is opened in write mode, writing the file to disk./vsicurl/http://internal-host/) as the spatial lookup value to cause the Django process to make an outbound HTTP request./vsicurl/, /vsis3/, /vsigs/); unusual DNS lookups originating from the web server process.?point=/vsicurl/... or ?geom={"name":...}); SuspiciousOperation exceptions in Django logs (on patched systems, these indicate attempted exploitation)..py, .pyc, or configuration files with recent modification timestamps matching admin access times; new files in GDAL-writable locations with unusual names or contents.Upgrade Django to version 5.2.17 or 6.0.8 immediately, as these releases block str and dict types from reaching the GDALRaster constructor in spatial lookup contexts (Django Security Releases). If immediate patching is not possible, restrict access to the Django admin changelist for models with spatial fields, and ensure that staff users with view-only permissions are limited to trusted individuals. Note that this fix is a backward-incompatible change: applications that intentionally pass str, pathlib.Path, or dict values to spatial lookups must now explicitly wrap them in GDALRaster(). Earlier unsupported series (5.1.x, 5.0.x, 4.2.x) should be evaluated separately and upgraded to a supported, patched version. For defense-in-depth, consider restricting available GDAL drivers per GDAL security guidance (Django Commit f1949c1).
The Django project officially disclosed the vulnerability alongside three other security fixes in its August 4, 2026 security release announcement, rating this issue as "high" severity per its security policy (Django Security Releases). Red Hat tracked the issue as high priority in its Bugzilla and security advisory systems (Red Hat Bugzilla). SUSE issued a security update (SUSE-SU-2026:3503-1) for its python-django packages. Coverage appeared across security news outlets including The Hacker News, GBHackers, CyberPress, and CyberSecurityNews, with community commentary on Mastodon (infosec.exchange) and LinkedIn highlighting the RCE potential and urging immediate patching. The Ansible project also released updated dev tools (v26.8.0) addressing the dependency.
Fix availability across major Linux distributions and their releases.
bookworm
python-django
sid
python-django: 3:5.2.17-1
trixie
python-django
bionic (esm-infra)
python-django
devel
python-django
focal (esm-infra)
python-django
jammy
python-django
noble
python-django
resolute
python-django
trusty (esm-infra-legacy)
python-django
xenial (esm-infra-legacy)
python-django
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."