Junglewise Threat Intelligence

CVE-2026-6873: Django salt namespace collision in get_signed_cookie

CVE-2026-6873 · Severity: low · CVSS 3.1 · Published 2026-06-03

Technologies: Django Software Foundation Django, Django (PyPI). Vendors: Django Software Foundation, PyPI.

Executive brief

Django, a popular web framework, contains a flaw in how it handles signed cookies used to verify data integrity. An attacker could potentially reuse a security cookie in a different part of the application than intended by exploiting how the system generates internal security keys. This could lead to unauthorized access to specific data or features that rely on these cookies for validation.

Technical details

The `django.http.HttpRequest.get_signed_cookie` function in Django uses a non-injective salt derivation method by concatenating the cookie name and the salt argument. This flaw allows for salt namespace collisions where distinct `(name, salt)` pairs produce the same concatenated string. A remote attacker with low privileges can exploit this to use a signed cookie in a context different from the one where it was originally signed. The issue affects Django versions before 5.2.15 and 6.0.x before 6.0.6; older unsupported versions may also be impacted. Patches have been released in versions 5.2.15 and 6.0.6.

Affected products

  • Django Software Foundation Django < 5.2.15, >= 6.0.0, < 6.0.6

Timeline

  • 2026-06-03: advisory
  • 2026-06-03: disclosed
  • 2026-06-03: patched

References

Related threats