PT-2026-37078 · Django Software Foundation+3 · Django+3

·

CVE-2026-6907

·

Published

2026-05-05

·

Updated

2026-07-19

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Django versions 6.0 through 6.0.4 Django versions 5.2 through 5.2.13
Description An issue in django.middleware.cache.UpdateCacheMiddleware causes requests where the Vary header contains an asterisk ('*') to be erroneously cached. This behavior can lead to the storage and subsequent delivery of private data to unauthorized users.
Recommendations Update to version 6.0.5 for versions 6.0 through 6.0.4. Update to version 5.2.14 for versions 5.2 through 5.2.13.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10003
BIT-DJANGO-2026-6907
CVE-2026-6907
ECHO-7B00-51A9-54BE
GHSA-5HRC-GVXJ-W55P
OESA-2026-2217
OESA-2026-2218
OESA-2026-2219
OESA-2026-2220
OESA-2026-3074
OPENSUSE-SU-2026:10708-1
OPENSUSE-SU-2026:10709-1
OPENSUSE-SU-2026:10718-1
OPENSUSE-SU-2026:11270-1
OPENSUSE-SU-2026:20704-1
PYSEC-2026-55
SUSE-SU-2026:1740-1
USN-8232-1

Affected Products

Django
Linuxmint
Red Os
Ubuntu