Vulnerability GHSA-q238-5cxm-5c9h

Medium Risk
MEDIUM RISK
CVSS Score: 5.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 month ago
August 04, 2026 at 06:31 PM UTC
Django GeoDjango vulnerable to denial of service through deeply nested geometry collections
1.0.1 - 5.2.16 and 6.0a1 - 6.0.7 and 6.1a1 - 6.1
1.0.1 - 5.2.16 and 6.0a1 - 6.0.7 and 6.1a1 - 6.1

Summary

Django GeoDjango vulnerable to denial of service through deeply nested geometry collections

Details

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's django.contrib.gis.geos.GEOSGeometry is subject to a potential denial-of-service when parsing deeply nested GEOMETRYCOLLECTION objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the django.contrib.gis.forms.GeometryField form field are also affected. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue.

Impacted packages

Timeline

Published
1 month ago
August 04, 2026 at 06:31 PM UTC
Fixed (6.0.8)
1 month ago
August 04, 2026 at 03:03 PM UTC
Fixed (5.2.17)
1 month ago
August 04, 2026 at 03:03 PM UTC
Fixed (6.1.1)
28 days ago
September 02, 2026 at 05:20 PM UTC
Last Modified
3 hours ago
September 30, 2026 at 08:40 PM UTC