Executive brief
A vulnerability in Django's caching system could allow sensitive information to be accidentally shared between different users. When the system processes requests containing certain cookies, it may incorrectly store private responses in a shared cache, making them accessible to other visitors. This could lead to the exposure of private data or session information to unauthorized parties.
Technical details
A vulnerability exists in Django's UpdateCacheMiddleware and the cache_page() decorator where responses that vary on cookies are incorrectly cached when an incoming request contains unrelated cookies. This flaw in the cache key generation logic allows a remote attacker to potentially retrieve private data from a shared cache that was intended for a different user. The issue affects Django versions 5.2.x before 5.2.16 and 6.0.x before 6.0.7; older unsupported versions like 5.0.x and 4.2.x may also be vulnerable. Users are advised to upgrade to the patched versions (5.2.16 or 6.0.7) to ensure proper cache isolation.
Affected products
- Django Software Foundation Django 5.2 before 5.2.16, 6.0 before 6.0.7
Timeline
- 2026-07-07: disclosed
- 2026-07-07: advisory
- 2026-07-07: patched
References
- https://docs.djangoproject.com/en/dev/releases/security
- https://groups.google.com/g/django-announce
- https://www.djangoproject.com/weblog/2026/jul/07/security-releases
- https://github.com/django/django/commit/64f9a2b2283fde3ec69fb0dfe441cf0f6f411ba3
- https://github.com/django/django/commit/6e365f8d01f2ba0bbd90968d76a42600fb8bc4b1