A AegiFlow
LOWCVSS 2.3EPSS 0.4%

CVE-2026-48588

Django: cache middleware may expose private responses when unrelated request cookies are present

Published
2026-07-07
Modified
2026-08-07
EPSS percentile
29%
Aliases
GHSA-3h9f-r86x-qvjx
Sources
github-advisory

Summary

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIdjango5.2.16, 6.0.7

Remediation: Upgrade to 5.2.16 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.