An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.
Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Cantina for reporting this issue.
References
| Link | Resource |
|---|---|
| https://docs.djangoproject.com/en/dev/releases/security/ | Vendor Advisory |
| https://groups.google.com/g/django-announce | Third Party Advisory |
| https://www.djangoproject.com/weblog/2026/may/05/security-releases/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
07 May 2026, 14:20
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| CPE | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | |
| First Time |
Djangoproject
Djangoproject django |
|
| References | () https://docs.djangoproject.com/en/dev/releases/security/ - Vendor Advisory | |
| References | () https://groups.google.com/g/django-announce - Third Party Advisory | |
| References | () https://www.djangoproject.com/weblog/2026/may/05/security-releases/ - Vendor Advisory |
05 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-05 16:16
Updated : 2026-05-07 14:20
NVD link : CVE-2026-35192
Mitre link : CVE-2026-35192
CVE.ORG link : CVE-2026-35192
JSON object : View
Products Affected
djangoproject
- django
CWE
CWE-539
Use of Persistent Cookies Containing Sensitive Information
