DoS via recursive GEOSGeometry in Django 5.2.17 & 6.0.8 GeoDjango
CVE-2026-15830 Published on August 4, 2026
Potential denial-of-service vulnerability via nested geometry collections
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected.
Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.
Django would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue.
Timeline
Initial report received.
Vulnerability confirmed. 15 days later.
Security release issued. 12 days later.
Weakness Type
What is a Stack Exhaustion Vulnerability?
The product does not properly control the amount of recursion which takes place, consuming excessive resources, such as allocated memory or the program stack.
CVE-2026-15830 has been classified to as a Stack Exhaustion vulnerability or weakness.
Products Associated with CVE-2026-15830
Want to know whenever a new CVE is published for Django Project Django? stack.watch will email you.
Affected Versions
djangoproject Django:- Version 6.0 and below 6.0.8 is affected.
- Version 6.0.8 is unaffected.
- Version 5.2 and below 5.2.17 is affected.
- Version 5.2.17 is unaffected.