CVE-2026-15830
Received Received - Intake

Denial-of-Service in Django GEOSGeometry Parsing

Vulnerability report for CVE-2026-15830, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: Django Software Foundation

Description

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
django django to 5.2.17 (exc)
django django to 6.0.8 (exc)
django django 5.1
django django 5.0
django django 4.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial-of-service issue in Django versions 5.2 before 5.2.17 and 6.0 before 6.0.8. It occurs when GeoDjango's GEOSGeometry parses deeply nested GEOMETRYCOLLECTION objects in WKT, WKB, or hex-encoded WKB formats, causing unbounded recursion and a segmentation fault in the GEOS library. Spatial field lookups and GeometryField form fields are also affected.

Detection Guidance

This vulnerability affects Django versions 5.2 before 5.2.17 and 6.0 before 6.0.8, specifically when parsing deeply nested GEOMETRYCOLLECTION objects. To detect it, check your Django version with `python -c "import django; print(django.get_version())"`. If you are running an affected version, inspect any code or inputs that process spatial data via GEOSGeometry or GeometryField.

Impact Analysis

This vulnerability can cause system crashes or unresponsiveness when processing malicious or malformed spatial data. It may lead to denial-of-service conditions, disrupting services that rely on Django's GeoDjango functionality.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it is a technical DoS issue in Django's GIS components. However, unpatched systems could experience service disruptions, potentially impacting availability requirements under these regulations.

Mitigation Strategies

Upgrade Django to version 5.2.17 or later, or 6.0.8 or later. If upgrading is not immediately possible, avoid processing untrusted spatial data inputs, particularly GEOMETRYCOLLECTION objects, until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15830. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart