CVE-2026-6907
2.3
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 (Secondary)
Description
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.
`django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). This can lead to private data being stored and served.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Ahmad Sadeddin for reporting this issue.
Affected (2)
Products: Djangoproject: Django
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.2 to 5.2.14 |
References (3)
Source: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
Vendor Advisory
Source: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
Third Party Advisory
Source: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
Vendor Advisory
Timeline
No history available yet.