PT-2026-45944 · Django+1 · Django+1
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Django versions prior to 5.2.15
Django versions prior to 6.0.6
Description
The
django.utils.cache.has vary header() function does not strip leading or trailing whitespace from Vary response header values before comparison. This allows remote attackers to read cached responses by making requests to URLs that have whitespace-padded Vary header values.Recommendations
Update to version 5.2.15 or newer.
Update to version 6.0.6 or newer.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Django
Red Os