Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2026-35193

около 2 месяцев назад

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Shai Berger for reporting this issue.

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2026-35193

около 2 месяцев назад

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Shai Berger for reporting this issue.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2026-35193

около 2 месяцев назад

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Shai Berger for reporting this issue.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2026-35193

около 2 месяцев назад

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0 ...

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-qpc8-7fxc-cm4p

около 2 месяцев назад

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Shai Berger for reporting this issue.

CVSS3: 3.1
EPSS: Низкий
fstec логотип

BDU:2026-10403

около 2 месяцев назад

Уязвимость модуля django.middleware.cache.UpdateCacheMiddleware программной платформы для веб-приложений Django, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.1
EPSS: Низкий
redos логотип

ROS-20260707-73-0028

24 дня назад

Уязвимость python-django

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20937-1

около 2 месяцев назад

Security update for python-Django

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2318-1

около 2 месяцев назад

Security update for python-Django

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-35193

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Shai Berger for reporting this issue.

CVSS3: 3.1
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-35193

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Shai Berger for reporting this issue.

CVSS3: 3.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-35193

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Shai Berger for reporting this issue.

CVSS3: 3.1
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-35193

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0 ...

CVSS3: 3.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-qpc8-7fxc-cm4p

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Shai Berger for reporting this issue.

CVSS3: 3.1
0%
Низкий
около 2 месяцев назад
fstec логотип
BDU:2026-10403

Уязвимость модуля django.middleware.cache.UpdateCacheMiddleware программной платформы для веб-приложений Django, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.1
0%
Низкий
около 2 месяцев назад
redos логотип
ROS-20260707-73-0028

Уязвимость python-django

CVSS3: 5.3
0%
Низкий
24 дня назад
suse-cvrf логотип
openSUSE-SU-2026:20937-1

Security update for python-Django

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2318-1

Security update for python-Django

около 2 месяцев назад

Уязвимостей на страницу