GHSA-7h2m-m8vj-598hLow

Django Uses Persistent Cookies Containing Sensitive Information

Published
May 5, 2026
Last Modified
June 5, 2026

🔗 CVE IDs covered (1)

📋 Description

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but SESSION_SAVE_EVERY_REQUEST is True. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.

Django thanks Cantina for reporting this issue.

🎯 Affected products2

  • pip/Django:>= 6.0, < 6.0.5
  • pip/Django:>= 5.2, < 5.2.14

🔗 References (6)