Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
831 articles · 101718 vulns · 38/41 feeds (7d)
← Back to list
5.4
CVE-2026-1207KEVEXPLOITEDPATCHED
djangoproject · django

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the ban

Description

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

Affected Products

VendorProductVersions
djangoprojectdjango< 4.2.28, < 5.2.11, < 6.0.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
debiandebian linuxcert_advisory90%
fedorafedora linuxcert_advisory90%
open sourcedjangocert_advisory90%
red hatred hat enterprise linuxcert_advisory90%
sususe opensusecert_advisory90%

References

  • https://docs.djangoproject.com/en/dev/releases/security/(Vendor Advisory, Patch)
  • https://groups.google.com/g/django-announce(Release Notes)
  • https://www.djangoproject.com/weblog/2026/feb/03/security-releases/(Patch, Vendor Advisory)

Related News (1 articles)

Tier B
BSI Advisories14h ago
[UPDATE] [mittel] Django: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.15.4 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
4.2.285.2.116.0.2
CWECWE-89
PublishedFeb 3, 2026
Last enriched3h ago
Trending Score86
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-1285
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.chars()` and `Truncator.words()` methods (with `html=True`) and the `truncatechars_h
Trending: 26
HIGHCVE-2025-14550
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote attacker to cause a potential denial-of-service via a crafted request with multiple
Trending: 26
MEDIUMCVE-2026-1312
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, u
Trending: 22
MEDIUMCVE-2025-13473
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers.modwsgi.check_password()` function for authentication via `mod_wsgi` allows rem
Trending: 22
MEDIUMCVE-2026-1287
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted
Trending: 22

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Feb 3, 2026
Added to CISA KEV
Feb 3, 2026
Actively Exploited
Feb 4, 2026
Patch Available
Feb 4, 2026
Discovered by ZDM
Apr 1, 2026