PT-2026-37060 · Django Software Foundation+3 · Django+3

·

CVE-2026-35192

·

Published

2026-05-05

·

Updated

2026-07-19

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Django versions 6.0 through 6.0.4 Django versions 5.2 through 5.2.13
Description When SESSION SAVE EVERY REQUEST is set to True, response headers do not vary based on cookies if a session remains unmodified. This allows a remote attacker to steal a user's session after the victim visits a cached public page. This is a session fixation issue where a session identifier can be compromised via public cached content.
Recommendations Update Django versions 6.0 through 6.0.4 to version 6.0.5. Update Django versions 5.2 through 5.2.13 to version 5.2.14.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09702
BIT-DJANGO-2026-35192
CVE-2026-35192
ECHO-DA14-670E-14A1
GHSA-7H2M-M8VJ-598H
OESA-2026-2217
OESA-2026-2218
OESA-2026-2219
OESA-2026-2220
OESA-2026-3074
OPENSUSE-SU-2026:10708-1
OPENSUSE-SU-2026:10709-1
OPENSUSE-SU-2026:10718-1
OPENSUSE-SU-2026:11270-1
OPENSUSE-SU-2026:20704-1
PYSEC-2026-50
SUSE-SU-2026:1740-1
USN-8232-1

Affected Products

Django
Linuxmint
Red Os
Ubuntu