Executive brief
A vulnerability in the Django web framework could allow an attacker to hijack a user's active session. This occurs when a website is configured to save session data on every request and serves public pages through a cache. If a user visits a cached public page, their private session cookie may be inadvertently stored and later served to other visitors, leading to unauthorized account access.
Technical details
A session fixation/leakage vulnerability exists in Django when SESSION_SAVE_EVERY_REQUEST is set to True. In affected versions, response headers do not properly vary on cookies if a session is not modified during a request. This can cause downstream caches (like CDNs or local proxies) to store and serve a response containing a specific user's session cookie to other users who request the same public page. An attacker can then use the leaked cookie to impersonate the victim. The issue is fixed in Django 6.0.5 and 5.2.14.
Affected products
- Django Software Foundation Django >= 6.0, < 6.0.5
- Django Software Foundation Django >= 5.2, < 5.2.14
Timeline
- 2026-05-05: disclosed
- 2026-05-05: advisory
- 2026-05-05: patched