CVE-2026-35192Disclosure(djangoproject / django)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-539

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • django

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
django

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-05: 1Technical Details · 2026-05-05: 105-05
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Open Source Security mailing list@oss_security
    Disclosure

    Django https://www.openwall.com/lists/oss-security/2026/05/05/8 CVE-2026-5766: DoS in ASGI requests via file upload limit bypass CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST CVE-2026-6907: Data exposure due to incorrect handling of `Vary: *` in UpdateCacheMiddleware

    Post summary

    The tweet serves as a brief disclosure of three Django CVEs, outlining the primary exploitation vectors but lacking PoC, exploit code, active exploitation reports, or patch information.

    01062522
    4.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdjangoprojectdjango---

Explore more