Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

github логотип

GHSA-crhf-3pfg-w68w

2 месяца назад

Django: GDALRaster may over-read heap memory when constructed from bytes

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2026-53877

2 месяца назад

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2026-53877

2 месяца назад

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2026-53877

2 месяца назад

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2026-53877

2 месяца назад

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2. ...

CVSS3: 4.8
EPSS: Низкий
redos логотип

ROS-20260819-80-0076

27 дней назад

Уязвимость python-django

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260819-73-0076

27 дней назад

Уязвимость python-django

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2819-1

2 месяца назад

Security update for python-Django

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21313-1

2 месяца назад

Security update for python-Django

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-crhf-3pfg-w68w

Django: GDALRaster may over-read heap memory when constructed from bytes

CVSS3: 4.8
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-53877

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.

CVSS3: 4.8
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-53877

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.

CVSS3: 4.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-53877

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.

CVSS3: 4.8
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-53877

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2. ...

CVSS3: 4.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260819-80-0076

Уязвимость python-django

CVSS3: 6.5
0%
Низкий
27 дней назад
redos логотип
ROS-20260819-73-0076

Уязвимость python-django

CVSS3: 6.5
0%
Низкий
27 дней назад
suse-cvrf логотип
SUSE-SU-2026:2819-1

Security update for python-Django

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21313-1

Security update for python-Django

2 месяца назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.