The Django development team has released Django 6.0.8 and Django 5.2.17 to fix four security vulnerabilities affecting supported versions of the Python web framework. Developers and administrators are urged to upgrade as soon as possible, especially where Django GIS features or the built-in admin interface are exposed to staff users. The most severe issue, tracked as CVE-2026-15307, is rated high severity. It affects Django spatial lookups that process raster-related values through GDALRaster. Previously, spatial lookups could accept string and dictionary values when they represented rasters. Depending on the selected raster driver, a malicious value could trigger a file write on the server or make a network request using the...
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!