CVE-2026-6907General(djangoproject / django)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). This can lead to private data being stored and served. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmad Sadeddin for reporting this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-524

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • django

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
django

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-05: 1Technical Details · 2026-05-05: 105-05
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Open Source Security mailing list@oss_security
    General

    Django https://www.openwall.com/lists/oss-security/2026/05/05/8 CVE-2026-5766: DoS in ASGI requests via file upload limit bypass CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST CVE-2026-6907: Data exposure due to incorrect handling of `Vary: *` in UpdateCacheMiddleware

    Post summary

    The text lists three Django CVEs with technical details of vulnerabilities, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    01062522
    4.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdjangoprojectdjango---

Explore more