A AegiFlow
MEDIUMCVSS 6.3EPSS 0.3%

CVE-2026-53877

Django: GDALRaster may over-read heap memory when constructed from bytes

Published
2026-07-07
Modified
2026-08-07
EPSS percentile
20%
Aliases
GHSA-crhf-3pfg-w68w
Sources
github-advisory

Summary

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIdjango5.2.16, 6.0.7

Remediation: Upgrade to 5.2.16 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.