{"dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": {"cveId": "CVE-2026-15830", "assignerOrgId": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92", "state": "PUBLISHED", "assignerShortName": "DSF", "dateReserved": "2026-07-15T15:01:48.803Z", "datePublished": "2026-08-04T15:48:34.075Z", "dateUpdated": "2026-08-04T17:21:28.167Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "6a34fbeb-21d4-45e7-8e0a-62b95bc12c92", "shortName": "DSF", "dateUpdated": "2026-08-04T15:48:34.075Z"}, "problemTypes": [{"descriptions": [{"lang": "en", "cweId": "CWE-674", "description": "CWE-674: Uncontrolled Recursion", "type": "CWE"}]}], "impacts": [{"capecId": "CAPEC-230", "descriptions": [{"lang": "en", "value": "CAPEC-230: Serialized Data with Nested Payloads"}]}], "title": "Potential denial-of-service vulnerability via nested geometry collections", "metrics": [{"other": {"content": {"value": "moderate", "namespace": "https://docs.djangoproject.com/en/dev/internals/security/#security-issue-severity-levels"}, "type": "Django severity rating"}}, {"cvssV3_1": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "baseScore": 5.3, "baseSeverity": "MEDIUM"}}, {"cvssV4_0": {"version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N", "baseScore": 6.9, "baseSeverity": "MEDIUM"}}], "descriptions": [{"lang": "en", "value": "An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.\nGeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected.\nEarlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.\nDjango would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue.", "supportingMedia": [{"type": "text/html", "base64": false, "value": "<p>An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.</p><p>GeoDjango&#x27;s <code>django.contrib.gis.geos.GEOSGeometry</code> is subject to a potential denial-of-service when parsing deeply nested <code>GEOMETRYCOLLECTION</code> objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the <code>django.contrib.gis.forms.GeometryField</code> form field are also affected.</p><p>Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.</p><p>Django would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue.</p>"}]}], "affected": [{"collectionURL": "https://pypi.org/project/Django/", "defaultStatus": "unaffected", "packageName": "django", "product": "Django", "repo": "https://github.com/django/django/", "vendor": "djangoproject", "versions": [{"status": "affected", "version": "6.0", "lessThan": "6.0.8", "versionType": "python"}, {"status": "unaffected", "version": "6.0.8", "versionType": "python"}, {"status": "affected", "version": "5.2", "lessThan": "5.2.17", "versionType": "python"}, {"status": "unaffected", "version": "5.2.17", "versionType": "python"}]}], "references": [{"url": "https://docs.djangoproject.com/en/dev/releases/security/", "name": "Django security archive", "tags": ["vendor-advisory"]}, {"url": "https://groups.google.com/g/django-announce", "name": "Django releases announcements", "tags": ["mailing-list"]}, {"tags": ["patch"], "url": "https://github.com/django/django/commit/d2e59b77fe18de318a8272c2a7bbc798d84d1d0d"}, {"tags": ["patch"], "url": "https://github.com/django/django/commit/9e4a3f186b6b07b483bfd9195ea06734663fcd06"}, {"tags": ["patch"], "url": "https://github.com/django/django/commit/6af5da31775417c610dbf9c3f1b5b8333d42daf6"}, {"tags": ["patch"], "url": "https://github.com/django/django/commit/ba80833fa656dd09660b97c4429331067db1b080"}, {"url": "https://www.djangoproject.com/weblog/2026/aug/04/security-releases/", "name": "Django security releases issued: 6.0.8 and 5.2.17", "tags": ["vendor-advisory"]}], "credits": [{"lang": "en", "type": "reporter", "value": "Andrew MacPherson and kimchunbok_"}, {"lang": "en", "type": "remediation developer", "value": "Jacob Walls"}, {"lang": "en", "type": "coordinator", "value": "Natalia Bidart"}], "timeline": [{"lang": "en", "time": "2026-07-08T00:00:00.000Z", "value": "Initial report received."}, {"lang": "en", "time": "2026-07-23T00:00:00.000Z", "value": "Vulnerability confirmed."}, {"lang": "en", "time": "2026-08-04T10:00:00.000Z", "value": "Security release issued."}], "datePublic": "2026-08-04T10:00:00.000Z", "source": {"discovery": "EXTERNAL"}, "x_generator": {"engine": "cvelib 1.8.0"}}, "adp": [{"metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2026-08-04T17:16:11.996083Z", "id": "CVE-2026-15830", "options": [{"Exploitation": "none"}, {"Automatable": "yes"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-08-04T17:21:28.167Z"}}]}}