Количество 9
Количество 9
CVE-2026-48588
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue.
CVE-2026-48588
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue.
CVE-2026-48588
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue.
CVE-2026-48588
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2. ...
ROS-20260819-80-0075
Уязвимость python-django
ROS-20260819-73-0075
Уязвимость python-django
GHSA-3h9f-r86x-qvjx
Django: cache middleware may expose private responses when unrelated request cookies are present
SUSE-SU-2026:2819-1
Security update for python-Django
openSUSE-SU-2026:21313-1
Security update for python-Django
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-48588 An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue. | CVSS3: 3.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-48588 An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue. | CVSS3: 3.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-48588 An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue. | CVSS3: 3.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-48588 An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2. ... | CVSS3: 3.1 | 0% Низкий | 2 месяца назад | |
ROS-20260819-80-0075 Уязвимость python-django | CVSS3: 5.3 | 0% Низкий | 27 дней назад | |
ROS-20260819-73-0075 Уязвимость python-django | CVSS3: 5.3 | 0% Низкий | 27 дней назад | |
GHSA-3h9f-r86x-qvjx Django: cache middleware may expose private responses when unrelated request cookies are present | CVSS3: 3.1 | 0% Низкий | 2 месяца назад | |
SUSE-SU-2026:2819-1 Security update for python-Django | 2 месяца назад | |||
openSUSE-SU-2026:21313-1 Security update for python-Django | 2 месяца назад |
Уязвимостей на страницу