cbcvebase.
CVE-2026-53877
published 2026-07-07

CVE-2026-53877: An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed…

PriorityP425medium4.8CVSS 3.1
AVNACHPRNUINSUCLINAL
EPSS
0.29%
21.1th percentile
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.

Affected

21 ranges
VendorProductVersion rangeFixed in
ansible-automation-platform-24lightspeed-rhel8
ansible-automation-platform-25lightspeed-rhel8
ansible-automation-platform-26controller-rhel9
ansible-automation-platform-26eda-controller-rhel9
ansible-automation-platform-26gateway-rhel9
ansible-automation-platform-26hub-rhel9
ansible-automation-platform-26lightspeed-rhel9
ansible-automation-platform-27aap-cloud-billing-rhel9
ansible-automation-platform-27controller-rhel9
ansible-automation-platform-27eda-controller-rhel9
ansible-automation-platform-27gateway-rhel9
ansible-automation-platform-27hub-rhel9
ansible-automation-platform-27lightspeed-rhel9
ansible-automation-platform-27metrics-service-rhel9
ansible-automation-platform-tech-previewmetrics-service-rhel9
ansible-automation-platformautomation-dashboard-rhel9
ansible-automation-platformbootc-automation-portal-rhel9
discoverydiscovery-server-rhel9
djangoprojectdjango>= 5.2 < 5.2.165.2.16
djangoprojectdjango>= 6.0 < 6.0.76.0.7
satelliteiop-advisor-backend-rhel9

CVSS provenance

nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.