Server-Side Request Forgery (SSRF) in Django - CVE-2026-87890
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to induce server-side network requests.
nThe vulnerability exists due to acceptance of raster byte values without explicit GDALRaster wrapping in Django spatial lookups when preparing lookups from attacker-controlled bytes. A remote attacker can supply a VRT document referencing an external raster source to induce server-side network requests.
nExploitation requires an application to pass attacker-controlled bytes directly to a spatial lookup. GDAL opens these values through its in-memory virtual filesystem, and the resulting requests run as the Django process user.