CVE-2026-48588

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-07 15:16

Updated : 2026-07-09 13:01


NVD link : CVE-2026-48588

Mitre link : CVE-2026-48588

CVE.ORG link : CVE-2026-48588


JSON object : View

Products Affected

djangoproject

  • django
CWE
CWE-524

Use of Cache Containing Sensitive Information