An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28.
Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Tarek Nakkouch for reporting this issue.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue. | |
| Title | Potential SQL injection via raster lookups on PostGIS | |
| Weaknesses | CWE-89 | |
| References |
|
Status: PUBLISHED
Assigner: DSF
Published:
Updated: 2026-02-03T16:21:08.811Z
Reserved: 2026-01-19T20:14:06.262Z
Link: CVE-2026-1207
No data.
Status : Awaiting Analysis
Published: 2026-02-03T15:16:13.433
Modified: 2026-02-03T16:44:03.343
Link: CVE-2026-1207
No data.
OpenCVE Enrichment
No data.