PT-2026-56195 · Django+1 · Django+1

·

CVE-2026-48588

·

Published

2026-07-07

·

Updated

2026-08-19

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Django versions 6.0 through 6.0.6 Django versions 5.2 through 5.2.15
Description UpdateCacheMiddleware and the cache page() decorator cache responses that vary on cookies when the incoming request contains unrelated cookies. This behavior allows remote attackers to access private data stored in the shared cache.
Recommendations Update Django versions 6.0 through 6.0.6 to version 6.0.7. Update Django versions 5.2 through 5.2.15 to version 5.2.16.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DJANGO-2026-48588
CVE-2026-48588
ECHO-1B5A-EE63-2C52
GHSA-3H9F-R86X-QVJX
OESA-2026-3074
OESA-2026-3075
OESA-2026-3076
OESA-2026-3077
OESA-2026-3078
OPENSUSE-SU-2026:11235-1
OPENSUSE-SU-2026:11236-1
OPENSUSE-SU-2026:11248-1
OPENSUSE-SU-2026:11270-1
OPENSUSE-SU-2026:21313-1
PYSEC-2026-2090
SUSE-SU-2026:2819-1

Affected Products

Django
Red Os