Django · Django · CVE-2026-48588
**Name of the Vulnerable Software and Affected Versions**
Django versions 6.0 through 6.0.6
Django versions 5.2 through 5.2.15
**Description**
`UpdateCacheMiddleware` and the `cache page()` decorator cache responses that vary on cookies when the incoming request contains unrelated cookies. This behavior allows remote attackers to access private data stored in the shared cache.
**Recommendations**
Update Django versions 6.0 through 6.0.6 to version 6.0.7.
Update Django versions 5.2 through 5.2.15 to version 5.2.16.