CVE-2026-48588

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*

History

09 Jul 2026, 13:01

Type Values Removed Values Added
CPE cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
First Time Djangoproject
Djangoproject django
References () https://docs.djangoproject.com/en/dev/releases/security/ - () https://docs.djangoproject.com/en/dev/releases/security/ - Patch, Vendor Advisory
References () https://groups.google.com/g/django-announce - () https://groups.google.com/g/django-announce - Release Notes
References () https://www.djangoproject.com/weblog/2026/jul/07/security-releases/ - () https://www.djangoproject.com/weblog/2026/jul/07/security-releases/ - Vendor Advisory, Patch

07 Jul 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-07 15:16

Updated : 2026-07-09 13:01


NVD link : CVE-2026-48588

Mitre link : CVE-2026-48588

CVE.ORG link : CVE-2026-48588


JSON object : View

Products Affected

djangoproject

  • django
CWE
CWE-524

Use of Cache Containing Sensitive Information