CVE-2026-48588Low· 3.1▾ SunlitDjango: cache middleware may expose private responses when unrelated request cookies are present
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.4%
0.4% → 0.4%
Last analysed / modified upstream
3.1 → 5.3
low → medium
5.3 → 3.1
medium → low
3.1 → 5.3
low → medium
5.3 → 3.1
medium → low
3.1 → 5.3
low → medium
5.3 → 3.1
medium → low
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.
UpdateCacheMiddleware and the cache_page() decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Chris Whyland for reporting this issue.
django < 5.2.16django >= 6.0.0, < 6.0.7Upgrade to a patched release:
django 5.2.16django 6.0.7Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-5766Medium· 5.3Django has an Improper Handling of Length Parameter Inconsistency
CVE-2025-64460MediumDjango is vulnerable to DoS via XML serializer text extraction
CVE-2025-13372Medium· 4.3Django is vulnerable to SQL injection in column aliases
CVE-2025-64458High· 7.5Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2024-56374Medium· 5.8Django has a potential denial-of-service vulnerability in IPv6 validation
CVE-2025-26699Medium· 5.0Django vulnerable to Allocation of Resources Without Limits or Throttling