CVE-2026-1207 describes a SQL injection vulnerability in Django's RasterField, specifically impacting raster lookups when used with PostGIS. This flaw allows remote attackers to inject SQL via the band index parameter, affecting Django versions 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28, with older unsupported series also potentially vulnerable. The vulnerability has a CVSS score of 5.4 (MEDIUM), indicating a network-based attack with low complexity and requiring low privileges. Successful exploitation could lead to limited disclosure of information and limited integrity impact. While there is no evidence of active exploitation (KEV: No), a Nuclei template exists for detecting this high-severity SQL injection. The CVE has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.2, < 4.2.28CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | ||
>= 5.2, < 5.2.11CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | ||
>= 6.0, < 6.0.2CPE matchmatch criteria | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.