PT-2026-37060 · Django Software Foundation+2 · Django+2

Cantina

+2

·

Published

2026-05-05

·

Updated

2026-05-09

·

CVE-2026-35192

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Django versions 6.0 through 6.0.4 Django versions 5.2 through 5.2.13
Description When SESSION SAVE EVERY REQUEST is set to True, response headers do not vary based on cookies if a session remains unmodified. This allows a remote attacker to steal a user's session after the victim visits a cached public page. This is a session fixation issue where a session identifier can be compromised via public cached content.
Recommendations Update Django versions 6.0 through 6.0.4 to version 6.0.5. Update Django versions 5.2 through 5.2.13 to version 5.2.14.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DJANGO-2026-35192
CVE-2026-35192
GHSA-7H2M-M8VJ-598H
OESA-2026-2217
OESA-2026-2218
OESA-2026-2219
OESA-2026-2220
OPENSUSE-SU-2026:10708-1
OPENSUSE-SU-2026:10709-1
OPENSUSE-SU-2026:10718-1
PYSEC-2026-50
USN-8232-1

Affected Products

Django
Linuxmint
Ubuntu