Количество 10
Количество 10
BDU:2026-10478
Уязвимость функции django.utils.cache.has_vary_header() программной платформы для веб-приложений Django, позволяющая нарушителю раскрыть защищаемую информацию
ROS-20260707-73-0029
Уязвимость python-django
CVE-2026-48587
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Navid Rezazadeh for reporting this issue.
CVE-2026-48587
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Navid Rezazadeh for reporting this issue.
CVE-2026-48587
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Navid Rezazadeh for reporting this issue.
CVE-2026-48587
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0 ...
ROS-20260707-80-0027
Уязвимость python-django
GHSA-923m-gv2p-w5qp
Django: has_vary_header may expose cached responses when Vary values contain whitespace
openSUSE-SU-2026:20937-1
Security update for python-Django
SUSE-SU-2026:2318-1
Security update for python-Django
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-10478 Уязвимость функции django.utils.cache.has_vary_header() программной платформы для веб-приложений Django, позволяющая нарушителю раскрыть защищаемую информацию | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
ROS-20260707-73-0029 Уязвимость python-django | CVSS3: 5.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-48587 An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Navid Rezazadeh for reporting this issue. | CVSS3: 3.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-48587 An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Navid Rezazadeh for reporting this issue. | CVSS3: 3.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-48587 An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Navid Rezazadeh for reporting this issue. | CVSS3: 3.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-48587 An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0 ... | CVSS3: 3.1 | 0% Низкий | 3 месяца назад | |
ROS-20260707-80-0027 Уязвимость python-django | CVSS3: 5.3 | 0% Низкий | 2 месяца назад | |
GHSA-923m-gv2p-w5qp Django: has_vary_header may expose cached responses when Vary values contain whitespace | CVSS3: 3.1 | 0% Низкий | 3 месяца назад | |
openSUSE-SU-2026:20937-1 Security update for python-Django | 3 месяца назад | |||
SUSE-SU-2026:2318-1 Security update for python-Django | 3 месяца назад |
Уязвимостей на страницу