PT-2026-37060 · Django Software Foundation+2 · Django+2
Cantina
+2
·
Published
2026-05-05
·
Updated
2026-05-09
·
CVE-2026-35192
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Django versions 6.0 through 6.0.4
Django versions 5.2 through 5.2.13
Description
When
SESSION SAVE EVERY REQUEST is set to True, response headers do not vary based on cookies if a session remains unmodified. This allows a remote attacker to steal a user's session after the victim visits a cached public page. This is a session fixation issue where a session identifier can be compromised via public cached content.Recommendations
Update Django versions 6.0 through 6.0.4 to version 6.0.5.
Update Django versions 5.2 through 5.2.13 to version 5.2.14.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Django
Linuxmint
Ubuntu