AUGUST 27, 2026
Live Feed
Back to database
Case File

CVE-2026-53877

MEDIUM · CVSS 4.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

Django versions 6.0 prior to 6.0.7 and 5.2 prior to 5.2.16 are vulnerable due to an over-read issue in the `GDALRaster` class, which can lead to the disclosure of adjacent memory or potential service degradation through segmentation faults. Organizations using these versions should prioritize patching to mitigate risks associated with data exposure and application stability. Additionally, users of earlier, unsupported Django series may also be at risk and should assess their environments accordingly.

CVE
CVE-2026-53877
Severity
MEDIUM
CVSS
4.8
EPSS
0.28%

Original NVD Description

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)