StackRadar

CVE-2026-15307

High

Advisory

Published 4 Aug 2026In the index since 1 Oct 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.011
64th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
117
of 17,966 indexed, latest versions
Container images
113
deployed by those charts
Fix available
1 of 1
affected package

Django GeoDjango spatial lookups allow file writes and outbound requests through GDAL raster parsing

Carried by container images the latest versions of 117 of 17,966 indexed charts deploy, on 113 images.

Affected packageAffected versionsFixed inImages
djangopypi1.11.11, 1.11.24, 1.11.29, 2.2.13+68 more5.2.17, 6.0.8113
OSV records
GHSA-wvqv-fj8w-qmhm
Also known as
BIT-django-2026-15307

Charts affected

117 by stars
ChartLatestAffected imagesRadar Score
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
django@1.11.11
5.2.17

Open the chart page →

84,245
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
django@6.0
6.0.8

Open the chart page →

4,305
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
django@3.2.14
5.2.17

Open the chart page →

94,375
libretimepodzone-chartsVerified publisher0.4.11 of 9See more

libretime podzone-charts 0.4.1

1 of the 9 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
ghcr.io/libretime/libretime-api:latesteae026cc8909
django@4.2.23
5.2.17

Open the chart page →

12,041
reviewboardrock8sVerified publisher0.0.11 of 3See more

reviewboard rock8s 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
beanbag/reviewboard:latest6b840f546e1c
django@4.2.30
5.2.17

Open the chart page →

6,389
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
django@5.2.7
5.2.17

Open the chart page →

11,750
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
django@5.2.8
5.2.17

Open the chart page →

4,795
linkdingrubxkubeVerified publisher1.2.41 of 1See more

linkding rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.47.0e35cb50e0581
django@6.0.7
6.0.8

Open the chart page →

2,460
safe-config-servicesafe-global0.1.01 of 3See more

safe-config-service safe-global 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
django@6.0.5
6.0.8

Open the chart page →

1,926
safe-stacksafe-global0.1.02 of 9See more

safe-stack safe-global 0.1.0

2 of the 9 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
django@6.0.5
6.0.8
safeglobal/safe-transaction-service:latest7b576c73f865
django@5.2.16
5.2.17

Open the chart page →

20,611
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
safeglobal/safe-transaction-service:latest7b576c73f865
django@5.2.16
5.2.17

Open the chart page →

17,188
seafileseafileVerified publisher0.12.11 of 1See more

seafile seafile 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
django@4.2.15
5.2.17

Open the chart page →

77,112
backendsignalen4.25.01 of 4See more

backend signalen 4.25.0

1 of the 4 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
signalen/backend:2.50.1826bb090bc4e4
django@4.2.30
5.2.17

Open the chart page →

11,735
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
django@3.0.4
5.2.17

Open the chart page →

9,257
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
django@4.2.16
5.2.17

Open the chart page →

4,938
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
django@4.0.5
5.2.17

Open the chart page →

3,934
dingtalk-botxxl-job-adminVerified publisher0.1.31 of 2See more

dingtalk-bot xxl-job-admin 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-15307.

Container imageDigestPackageFixed in
dellnoantechnp/dingtalk-bot:v1.0.1034000bbcad5
django@5.2.9
5.2.17

Open the chart page →

3,565

Container images carrying it

113 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
django@5.2.7
5.2.17
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
django@5.2.7
5.2.17
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
django@4.0.6
5.2.17
1
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
django@4.2.13
5.2.17
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
django@4.2.7
5.2.17
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
django@5.2.7
5.2.17
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
django@5.2.13
5.2.17
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
django@6.0
6.0.8
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
django@4.2.16
5.2.17
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
django@4.2.18
5.2.17
1
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
django@5.2.3
5.2.17
1
ghcr.io/zazukoians/qlever-ui:v0.10.151a7ec1c2de4
django@5.2.12
5.2.17
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
django@4.2.21
5.2.17
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.