CVE-2026-15830General(djangoproject / django)

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch djangoproject django systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • django

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-08-04); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
django

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-08-04: 1Mentions · 2026-08-05: 1Mentions · 2026-08-10: 1Mentions · 2026-09-16: 1Patch / Workaround · 2026-08-05: 1Technical Details · 2026-08-05: 108-0408-0508-1009-16
Signal classification2 categories
General
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-041
General1
2026-08-051
Patch1
2026-08-101
General1
Full discourse4 posts
  • AndrewMohawk⁽ⁿᵘˡˡ⁾@AndrewMohawk
    General

    I really do think harnesses are falling away, but mines still going for now, forgot to add this to the list from Aug 04 CVE-2026-15830 -- https://www.djangoproject.com/weblog/2026/aug/04/security-releases/

    Post summary

    The text references the CVE-2026-15830 on a Django security releases page but offers no further technical or exploit details.

    1011401.3K
    5.4K followersView on X
  • AndrewMohawk⁽ⁿᵘˡˡ⁾ ✨ 𝓲𝓷 𝓿𝓮𝓰𝓪𝓼 ✨@AndrewMohawk
    General

    CVE-2026-15830 My lil robot still going on! https://t.co/WbRKXmpDo6

    Post summary

    The tweet references CVE-2026-15830 and includes a link, but provides no concrete information about PoC, exploit, or mitigation.

    0011001.3K
    5.4K followersView on X
  • Repojournal@repojournal
    Patch

    Django patched four critical vulnerabilities across admin and spatial query handling. CVE-2026-15920 tightens URL validation in display_for_field() to prevent malicious admin links. CVE-2026-15307 blocks raster strings and dicts in spatial lookups. CVE-2026-15830 mitigates DoS via nested geometry collections. CVE-2026-15337 hardens check_for_language() against DoS. All four added to the security archive. If you're running Django in production with admin or GIS enabled, patch today. #django https://repojournal.com/showcase/django/2026-08-05/django-patches-four-critical-vulnerabilities-in-admin-and-spatial-queries

    Post summary

    The post announces that Django has released patches for four critical admin and GIS-related CVEs and urges production users to apply them.

    0304055
    382 followersView on X
  • Django News@djangonewsbot

    [Django Fellow Reports] Django Fellow Report - Jacob Jacob reviewed six Django pull requests and authored changes covering GEOS 3.10 support removal and expanded WKT depth-check coverage related to CVE-2026-15830. https://forum.djangoproject.com/t/django-fellow-report-jacob-2026/43851/39

    01000192
    4.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdjangoprojectdjango---

Explore more