{"id":"CVE-2026-53877","aliases":["BIT-django-2026-53877","GHSA-crhf-3pfg-w68w","PYSEC-2026-2091"],"url":"https://o3.security/vulnerability/CVE-2026-53877","summary":"Heap buffer over-read in GDALRaster","details":"An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.\n`django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Bence Nagy for reporting this issue.","published":"2026-07-07T14:10:04.025Z","modified":"2026-08-12T03:51:43.923557496Z","cvss":null,"epss":{"score":0.00437,"percentile":0.37276,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"django","fixedVersion":"5.2.16"},{"ecosystem":"PyPI","name":"django","fixedVersion":"6.0.7"}],"fix":{"url":"https://github.com/django/django/commit/38dfbd27d7d4f4e6eaa087d7a90f2613fbf55b3a","label":"django/django@38dfbd2"},"references":[{"type":"WEB","url":"https://github.com/django/django/"},{"type":"ADVISORY","url":"https://docs.djangoproject.com/en/dev/releases/security/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53877.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53877"},{"type":"ADVISORY","url":"https://www.djangoproject.com/weblog/2026/jul/07/security-releases/"},{"type":"PACKAGE","url":"https://pypi.org/project/Django/"},{"type":"ARTICLE","url":"https://groups.google.com/g/django-announce"},{"type":"WEB","url":"https://github.com/django/django/commit/38dfbd27d7d4f4e6eaa087d7a90f2613fbf55b3a"},{"type":"WEB","url":"https://github.com/django/django/commit/6c66eb8cec52b303af85c2c6e4dd00aa37654dbc"},{"type":"WEB","url":"https://github.com/django/django/commit/6ca2bbe2efce21010eff48f1f36a3f621d698ed8"},{"type":"WEB","url":"https://docs.djangoproject.com/en/dev/releases/security"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2026-2091.yaml"},{"type":"WEB","url":"https://www.djangoproject.com/weblog/2026/jul/07/security-releases"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:43.923557496Z"}}