An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.
`django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Bence Nagy for reporting this issue.
References
| Link | Resource |
|---|---|
| https://docs.djangoproject.com/en/dev/releases/security/ | Patch Vendor Advisory |
| https://groups.google.com/g/django-announce | Release Notes |
| https://www.djangoproject.com/weblog/2026/jul/07/security-releases/ | Vendor Advisory Patch |
Configurations
Configuration 1 (hide)
|
History
09 Jul 2026, 12:59
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Djangoproject
Djangoproject django |
|
| References | () https://docs.djangoproject.com/en/dev/releases/security/ - Patch, Vendor Advisory | |
| References | () https://groups.google.com/g/django-announce - Release Notes | |
| References | () https://www.djangoproject.com/weblog/2026/jul/07/security-releases/ - Vendor Advisory, Patch | |
| CPE | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* |
07 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-07 15:16
Updated : 2026-07-09 12:59
NVD link : CVE-2026-53877
Mitre link : CVE-2026-53877
CVE.ORG link : CVE-2026-53877
JSON object : View
Products Affected
djangoproject
- django
CWE
CWE-805
Buffer Access with Incorrect Length Value
