An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.
`django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). This can lead to private data being stored and served.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Ahmad Sadeddin for reporting this issue.
References
| Link | Resource |
|---|---|
| https://docs.djangoproject.com/en/dev/releases/security/ | Vendor Advisory |
| https://groups.google.com/g/django-announce | Third Party Advisory |
| https://www.djangoproject.com/weblog/2026/may/05/security-releases/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
07 May 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://docs.djangoproject.com/en/dev/releases/security/ - Vendor Advisory | |
| References | () https://groups.google.com/g/django-announce - Third Party Advisory | |
| References | () https://www.djangoproject.com/weblog/2026/may/05/security-releases/ - Vendor Advisory | |
| First Time |
Djangoproject
Djangoproject django |
|
| CPE | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* |
05 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-05 16:16
Updated : 2026-05-07 14:16
NVD link : CVE-2026-6907
Mitre link : CVE-2026-6907
CVE.ORG link : CVE-2026-6907
JSON object : View
Products Affected
djangoproject
- django
CWE
CWE-524
Use of Cache Containing Sensitive Information
