PT-2026-56195 · Django+1 · Django+1
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Django versions 6.0 through 6.0.6
Django versions 5.2 through 5.2.15
Description
UpdateCacheMiddleware and the cache page() decorator cache responses that vary on cookies when the incoming request contains unrelated cookies. This behavior allows remote attackers to access private data stored in the shared cache.Recommendations
Update Django versions 6.0 through 6.0.6 to version 6.0.7.
Update Django versions 5.2 through 5.2.15 to version 5.2.16.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Django
Red Os