
Django https://www.openwall.com/lists/oss-security/2026/05/05/8 CVE-2026-5766: DoS in ASGI requests via file upload limit bypass CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST CVE-2026-6907: Data exposure due to incorrect handling of `Vary: *` in UpdateCacheMiddleware
Post summary
The Openwall mailing list announcement discloses three Django CVEs describing a DoS vulnerability, a session fixation flaw, and data exposure due to incorrect Vary header handling.
