GHSA-7h2m-m8vj-598hLow
Django Uses Persistent Cookies Containing Sensitive Information
🔗 CVE IDs covered (1)
📋 Description
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but SESSION_SAVE_EVERY_REQUEST is True. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django thanks Cantina for reporting this issue.
🎯 Affected products2
- pip/Django:>= 6.0, < 6.0.5
- pip/Django:>= 5.2, < 5.2.14
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-35192
- https://docs.djangoproject.com/en/dev/releases/security
- https://groups.google.com/g/django-announce
- https://www.djangoproject.com/weblog/2026/may/05/security-releases
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2026-50.yaml
- https://github.com/advisories/GHSA-7h2m-m8vj-598h