CVE-2026-15830
📛 CVE Title
Potential denial-of-service vulnerability via nested geometry collections
Description
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- DSF
- CVSS severity
- MEDIUM
- CVSS score
- 6.9 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N- Effective score
- 6.9 / 10 MEDIUM source: CNA overview
- CWE(s)
-
CWE-674 - Reserved
- 2026-07-15
- Published
- 2026-08-04 15:48 UTC
- Last updated
- 2026-08-04 17:21 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/15xxx/CVE-2026-15830.json
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| djangoproject | Django |
6.0 (affected),
6.0.8 (unaffected),
5.2 (affected),
5.2.17 (unaffected)
|
— |
Vendor references (7)
References embedded in the original CVE record by the assigning CNA.
- Django security archive vendor-advisory
- Django releases announcements mailing-list
- https://github.com/django/django/commit/d2e59b77fe18de318a8272c2a7bbc798d84d1d0d patch
- https://github.com/django/django/commit/9e4a3f186b6b07b483bfd9195ea06734663fcd06 patch
- https://github.com/django/django/commit/6af5da31775417c610dbf9c3f1b5b8333d42daf6 patch
- https://github.com/django/django/commit/ba80833fa656dd09660b97c4429331067db1b080 patch
- Django security releases issued: 6.0.8 and 5.2.17 vendor-advisory
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-15830.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-15830",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-04T17:16:11.996083Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-04T17:21:28.167Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://pypi.org/project/Django/",
"defaultStatus": "unaffected",
"packageName": "django",
"product": "Django",
"repo": "https://github.com/django/django/",
"vendor": "djangoproject",
"versions": [
{
"lessThan": "6.0.8",
"status": "affected",
"version": "6.0",
"versionType": "python"
},
{
"status": "unaffected",
"version": "6.0.8",
"versionType": "python"
},
{
"lessThan": "5.2.17",
"status": "affected",
"version": "5.2",
"versionType": "python"
},
{
"status": "unaffected",
"version": "5.2.17",
"versionType": "python"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Andrew MacPherson and kimchunbok_"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Jacob Walls"
},
{
"lang": "en",
"type": "coordinator",
"value": "Natalia Bidart"
}
],
"datePublic": "2026-08-04T10:00:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.</p><p>GeoDjango's <code>django.contrib.gis.geos.GEOSGeometry</code> is subject to a potential denial-of-service when parsing deeply nested <code>GEOMETRYCOLLECTION</code> objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the <code>django.contrib.gis.forms.GeometryField</code> form field are also affected.</p><p>Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.</p><p>Django would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue.</p>"
}
],
"value": "An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.\nGeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected.\nEarlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.\nDjango would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue."
}
],
"impacts": [
{
"capecId": "CAPEC-230",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-230: Serialized Data with Nested Payloads"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"namespace": "https://docs.djangoproject.com/en/dev/internals/security/#security-issue-severity-levels",
"value": "moderate"
},
"type": "Django severity rating"
}
},
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
}
},
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674: Uncontrolled Recursion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-04T15:48:34.075Z",
"orgId": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92",
"shortName": "DSF"
},
"references": [
{
"name": "Django security archive",
"tags": [
"vendor-advisory"
],
"url": "https://docs.djangoproject.com/en/dev/releases/security/"
},
{
"name": "Django releases announcements",
"tags": [
"mailing-list"
],
"url": "https://groups.google.com/g/django-announce"
},
{
"tags": [
"patch"
],
"url": "https://github.com/django/django/commit/d2e59b77fe18de318a8272c2a7bbc798d84d1d0d"
},
{
"tags": [
"patch"
],
"url": "https://github.com/django/django/commit/9e4a3f186b6b07b483bfd9195ea06734663fcd06"
},
{
"tags": [
"patch"
],
"url": "https://github.com/django/django/commit/6af5da31775417c610dbf9c3f1b5b8333d42daf6"
},
{
"tags": [
"patch"
],
"url": "https://github.com/django/django/commit/ba80833fa656dd09660b97c4429331067db1b080"
},
{
"name": "Django security releases issued: 6.0.8 and 5.2.17",
"tags": [
"vendor-advisory"
],
"url": "https://www.djangoproject.com/weblog/2026/aug/04/security-releases/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"timeline": [
{
"lang": "en",
"time": "2026-07-08T00:00:00.000Z",
"value": "Initial report received."
},
{
"lang": "en",
"time": "2026-07-23T00:00:00.000Z",
"value": "Vulnerability confirmed."
},
{
"lang": "en",
"time": "2026-08-04T10:00:00.000Z",
"value": "Security release issued."
}
],
"title": "Potential denial-of-service vulnerability via nested geometry collections",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92",
"assignerShortName": "DSF",
"cveId": "CVE-2026-15830",
"datePublished": "2026-08-04T15:48:34.075Z",
"dateReserved": "2026-07-15T15:01:48.803Z",
"dateUpdated": "2026-08-04T17:21:28.167Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}