Vulnerability GHSA-3h9f-r86x-qvjx

Low Risk
LOW RISK
CVSS Score: 3.1
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
2 months ago
July 07, 2026 at 03:32 PM UTC
Django: cache middleware may expose private responses when unrelated request cookies are present
1.0.1 - 5.2.15 and 6.0 - 6.0.6
1.0.1 - 5.2.15 and 6.0 - 6.0.6

Summary

Django: cache middleware may expose private responses when unrelated request cookies are present

Details

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. UpdateCacheMiddleware and the cache_page() decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue.

Impacted packages

Timeline

Published
2 months ago
July 07, 2026 at 03:32 PM UTC
Fixed (6.0.7)
2 months ago
July 07, 2026 at 01:51 PM UTC
Fixed (5.2.16)
2 months ago
July 07, 2026 at 01:52 PM UTC
Last Modified
20 days ago
September 10, 2026 at 03:51 AM UTC