CVE-2026-1207Disclosure(djangoproject / django)

HIGHCVSS 5.4 · MEDIUM

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch djangoproject django systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • django

Threat summary

  • Active exploitation appears in 9 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 25 mentions across 16 observed days

What's happening

  • Active exploitation reported across 9 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 24 signals
  • Disclosure: 10 classified signals
  • General: 4 classified signals
  • Peaked 3d ago at 4 mentions (2026-07-10); latest day: 1
  • 25 total mentions across 16 days

Affected systems

Products
django

Deep dive

Activity timeline25 mentions / 16d
01234Mentions · 2026-02-03: 1Mentions · 2026-02-05: 3Mentions · 2026-02-08: 1Mentions · 2026-02-09: 1Mentions · 2026-02-16: 1Mentions · 2026-02-28: 1Mentions · 2026-03-12: 1Mentions · 2026-03-15: 2Mentions · 2026-03-23: 1Mentions · 2026-03-24: 1Mentions · 2026-03-27: 3Mentions · 2026-03-31: 2Mentions · 2026-07-10: 4Mentions · 2026-07-11: 1Mentions · 2026-07-14: 1Mentions · 2026-07-21: 1PoC Mentioned / Linked · 2026-02-05: 2PoC Mentioned / Linked · 2026-03-15: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-03-24: 1Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-07-10: 4Active Exploitation · 2026-07-14: 1Active Exploitation · 2026-07-21: 1Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-07-10: 4Patch / Workaround · 2026-07-11: 1Patch / Workaround · 2026-07-21: 1Technical Details · 2026-02-05: 3Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-15: 2Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-27: 3Technical Details · 2026-03-31: 2Technical Details · 2026-07-10: 4Technical Details · 2026-07-11: 1Technical Details · 2026-07-14: 1Technical Details · 2026-07-21: 102-0302-0502-0802-0902-1602-2803-1203-1503-2303-2403-2703-3107-1007-1107-1407-21
Signal classification5 categories
Disclosure
1040.0%
Active Exploitation
936.0%
General
416.0%
Patch
14.0%
PoC
14.0%
Referenced assets21 URLs
Classification over time
DateTotalLabels
2026-02-031
Disclosure1
2026-02-053
Disclosure2General1
2026-02-081
Disclosure1
2026-02-091
Disclosure1
2026-02-161
General1
2026-02-281
Patch1
2026-03-121
General1
2026-03-152
General1PoC1
2026-03-231
Active Exploitation1
2026-03-241
Active Exploitation1
2026-03-273
Active Exploitation1Disclosure2
2026-03-312
Disclosure2
2026-07-104
Active Exploitation4
2026-07-111
Disclosure1
2026-07-141
Active Exploitation1
2026-07-211
Active Exploitation1
Full discourse20 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    6 CVEs in Django https://www.openwall.com/lists/oss-security/2026/02/03/1 CVE-2025-13473: Username enumeration through timing difference in mod_wsgi authentication handler CVE-2025-14550: Potential DoS via repeated headers when using ASGI CVE-2026-1207: Potential SQL injection via raster lookups on PostGIS

    Post summary

    The text announces six new Django CVEs, detailing three specific issues: username enumeration, denial of service via repeated headers, and a potential SQL injection in PostGIS raster lookups.

    14081879
    4.4K followersView on X
  • Aikido Security@AikidoSecurity
    Disclosure

    smart AI will increase the volume of CVE. Findings such as CVE-2026-1207, a SQL injection in django that went unnoticed for 3 years Zen python users were protected the entire time Modern ADR protects against negative-day vulnerabilities

    Post summary

    The text announces the discovery of CVE-2026-1207, a Django SQL injection that went undetected for three years, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    101831.5K
    6.1K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    Django SQL Injection in RasterField lookup (CVE-2026-1207) https://vulnerabletarget.com/VT-2026-1207

    Post summary

    A new Django SQL Injection vulnerability (CVE‑2026‑1207) affecting RasterField lookup has been disclosed, with a link that likely contains proof‑of‑concept details.

    03053804
    32.7K followersView on X
  • Clandestine@akaclandestine
    Disclosure

    Django SQL Injection in RasterField lookup (CVE-2026-1207) // VT https://vulnerabletarget.com/detail.html?id=vt-2026-1207

    Post summary

    The tweet announces a newly identified Django SQL injection vulnerability (CVE‑2026‑1207) affecting the RasterField lookup, but provides no further technical details, PoC, exploit code, or mitigation information.

    000641.0K
    61.1K followersView on X
  • Netlas.io@Netlas_io
    General

    CVE-2026-1207, -1285, -1287 and other: Multiple vulnerabilities in Django Framework, 5.3 - 7.5 rating❗️ Several vulnerabilities in Django allow attackers to perform SQL injection and DoS attacks. Search at http://Netlas.io: 👉 Link: https://nt.ls/SOxq1

    Post summary

    Multiple Django vulnerabilities (CVE-2026-1207, -1285, -1287) allow SQL injection and DoS, with ratings 5.3–7.5; no PoC, exploit code, or patch details are provided.

    04051713
    7.2K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    CVE-2026-1207 is a Django SQL injection flaw (CVSS 8.3) in PostGIS raster lookups. Canada's CCCS says it is exploited in the wild. Patch now. #Django #SQLInjection #CVE20261207 #PostGIS #InfoSec http://securityonline.info/django-sql-injection-cve-2026-1207/

    Post summary

    The post reports that CVE-2026-1207, a Django/PostGIS SQL injection, is actively exploited worldwide and that a patch is now available.

    01152686
    12.9K followersView on X
  • ET Labs@ET_Labs
    General

    50 new OPEN, 146 new PRO (50 + 96) TrustConnect RAT, RMM Domain/TLS SNI, CVE-2026-1207 (Django SQL Injection), Lumma Stealer, TA569, and more. https://community.emergingthreats.net/t/ruleset-update-summary-2026-02-16-v11126/3200

    Post summary

    The update briefly lists CVE‑2026‑1207 as a Django SQL Injection but provides no additional details on exploitation, patches, or PoCs.

    02130419
    5.7K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    Django SQL Injection in RasterField lookup (CVE-2026-1207) https://vulnerabletarget.com/VT-2026-1207

    Post summary

    The post announces a new SQL injection vulnerability in Django’s RasterField lookup (CVE‑2026‑1207) but does not provide a PoC or exploit details.

    01031431
    33.3K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-1207 - high 🚨 Django RasterField - SQL Injection > Django < 6.0.2, < 5.2.11, and < 4.2.28 contains a SQL injection caused by improper sa... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-1207 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2026-1207 is a SQL injection vulnerability in Django RasterField affecting versions below 6.0.2, 5.2.11, and 4.2.28; the post merely discloses the issue with no evidence of an exploit or patch.

    01012167
    890 followersView on X
  • Aikido Security@AikidoSecurity
    Disclosure

    https://nvd.nist.gov/vuln/detail/CVE-2026-1207

    Post summary

    The NVD entry for CVE‑2026‑1207 offers a formal disclosure with technical details and vendor patch references, but it provides no PoC, exploit code, or evidence of active exploitation.

    10010174
    5.8K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    Django の脆弱性 CVE-2026-1207 が FIX:GIS モジュールに影響を及ぼす SQLi https://iototsecnews.jp/2026/07/10/django-sql-injection-vulnerability-actively-exploited-in-the-wild/ Web アプリケーションの開発で広く使われている Django ですが、 地理空間データを扱う専門的な機能の隙を突かれ、データベースを不正に操作されてしまうリスクが浮き彫りになりました。ユーザーからの入力を十分に検証しきれない仕組みが背景にあり、 悪意のリクエストにより大切な情報の窃取や改竄が生じると想定されます。この脆弱性 CVE-2026-1207 への具体的な対応策として、開発元が配布している修正済みの安全なバージョンへ速やかにアップデートすることが何よりも確実です。あわせて、不審なアクセスを遮断する WAF の導入や、 予期せぬエラーログに対する監視体制を整えることで、 日々の運用を強固にできます。 #CVE20261207 #Django #Vulnerability

    Post summary

    The post reports that Django’s CVE‑2026‑1207, a GIS module SQL injection, is actively exploited in the wild and recommends immediate patching along with WAF and logs monitoring.

    01000218
    500 followersView on X
  • RootNik Labs@rootniklabs
    Disclosure

    🚨 Security Alert | CVE-2026-1207 High-severity SQL Injection (CWE-89) affecting Django 4.2, 5.2 & 6.0. Exploitation may lead to unauthorized database access, data exposure & service disruption. Patch immediately. #CyberSecurity #Django #CVE20261207 #ROOTNIKLABS #VAPT #msme https://t.co/liMLvR5b0k

    Post summary

    A high‑severity SQL injection vulnerability (CVE‑2026‑1207) affecting Django 4.2‑6.0 has been disclosed and users are urged to patch immediately.

    0001060
    273 followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    DjangoのSQLインジェクション脆弱性Flaw CVE-2026-1207が悪用されている。PostGISデータベースで動作している場合のRasterFieldルックアップにおいて、band indexパラメータがバインド変数になっておらずインラインなのが悪い。2/3修正済み。 https://securityonline.info/django-sql-injection-cve-2026-1207/

    Post summary

    CVE-2026-1207, a Django SQL injection due to an inline band index parameter in PostGIS RasterField, is reported as actively exploited; partial patches are announced, but no explicit PoC or exploit code is disclosed.

    00010821
    7.6K followersView on X
  • CrowdSec@Crowd_Security
    Active Exploitation

    🚨 In this week’s threat alert, CrowdSec reports on CVE-2026-1207, a critical Django SQL injection vulnerability now actively exploited in the wild. Attackers are targeting GeoDjango setups using PostGIS with focused reconnaissance. Notably, this vulnerability hasn’t yet been added to the CISA KEV catalog. Learn how the vulnerability works and how to secure your systems in our latest article: https://www.crowdsec.net/vulntracking-report/cve-2026-1207 #CVE #CVE20261207 #ThreatAlert #ThreatIntel #cybersecurity

    Post summary

    CrowdSec alerts that CVE-2026-1207, a critical Django SQL injection affecting GeoDjango/PostGIS setups, is currently being exploited in the wild, with no patch yet available.

    00010223
    19.5K followersView on X
  • Rw-CSIRT@Rw_csirt
    Active Exploitation

    Security Alert: Active Exploitation of Django SQL Injection Vulnerability (CVE-2026-1207) https://cyber.gov.rw/updates/article/security-alert-active-exploitation-of-django-sql-injection-vulnerability-cve-2026-1207/

    Post summary

    The article alerts that CVE-2026-1207, a Django SQL injection flaw, is being actively exploited in the wild, with no patches or mitigations cited.

    0000066
    393 followersView on X
  • TECHEPAGES@techepages
    Active Exploitation

    ⚠️ A high-severity SQL injection flaw in Django (CVE-2026-1207) is now being actively exploited. It hits GeoDjango apps on the PostGIS backend — common in mapping platforms, location services, and geospatial analytics. 🎯 The bug is in how Django handles raster field lookups, specifically the "band" index parameter. Poor input validation lets attackers inject SQL to leak sensitive data or alter backend records. CrowdSec says exploitation started right after disclosure in late Feb 2026 — and it's targeted, not spray-and-pray. 🔹 Patched in Django 6.0.2, 5.2.11, and 4.2.28 — upgrade now 🔹 Only exploitable with GeoDjango + PostGIS, but impact is significant 🔹 Hunt logs for odd raster/"band" params and unexpected DB errors 🔹 Add input validation, disable debug in prod, deploy a WAF

    Post summary

    CVE-2026-1207 is a high‑severity SQL injection in Django’s GeoDjango raster lookups that is actively exploited in the wild; patches are available and additional mitigations are recommended.

    0000075
    19 followersView on X
  • The Daily Tech Feed@dailytechonx
    Active Exploitation

    A critical SQL injection vulnerability (CVE-2026-1207) in Django's GIS module is being actively exploited, targeting PostGIS-backed applications. Organizations must update to patched versions immediately to mitigate risks. #Django #SQLInjection #CVE20261207 #CyberSecurity #PostGIS #WebSecurity https://thedailytechfeed.com/django-sql-injection-vulnerability-actively-exploited/

    Post summary

    The post reports a SQL injection flaw in Django's GIS module that is actively being exploited and urges prompt patching.

    0000070
    505 followersView on X
  • Dr.Philippe Vynckier, CISSP - Influencer@PVynckier
    Active Exploitation

    CrowdSec confirme la première exploitation active de CVE-2026-1207, une faille d'injection SQL dans Django - IT SOCIAL https://itsocial.fr/cybersecurite/cybersecurite-actualites/crowdsec-confirme-la-premiere-exploitation-active-de-cve-2026-1207-une-faille-dinjection-sql-dans-django/

    Post summary

    CrowdSec confirms the first active exploitation of CVE-2026-1207, a SQL injection vulnerability in Django, with no mention of patches, mitigations, or exploit code.

    0000060
    24.0K followersView on X
  • Prevention Internet ®@Prevention_web
    Active Exploitation

    CrowdSec confirme la première exploitation active de CVE-2026-1207, une faille d'injection ... https://ift.tt/aJdkDIo #PreventionInternet #Cybersécurité

    Post summary

    CrowdSec reports the first live exploitation of CVE‑2026‑1207, an injection flaw, but provides no PoC, code, or patch information.

    0000033
    474 followersView on X
  • Marco Scandaletti@scandaletti
    General

    CVE-2026-1207 - Django SQLi Vulnerability https://dy.si/51eEdN2 https://t.co/GJDr5ujvYk

    Post summary

    The tweet references CVE-2026-1207 as a Django SQL injection vulnerability and includes links, but does not provide evidence of a PoC, exploit, patch, or active exploitation reports.

    0000037
    244 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdjangoprojectdjango---

Explore more