Executive brief
Django is a popular web framework used to build and power websites. A vulnerability in its caching system could cause the server to accidentally store and serve private, user-specific data to other visitors. This could lead to the exposure of sensitive information to unauthorized individuals.
Technical details
A vulnerability exists in Django's UpdateCacheMiddleware (CWE-524) where the middleware incorrectly caches responses even when the 'Vary' HTTP header contains an asterisk ('*'). According to HTTP standards, a 'Vary: *' header indicates that the response is uncacheable because it depends on information not present in the request headers. By caching these responses, Django may serve one user's private data to subsequent requesters. The issue affects Django versions 6.0.x before 6.0.5 and 5.2.x before 5.2.14; older unsupported versions may also be vulnerable. Patches are available in versions 6.0.5 and 5.2.14.
Affected products
- Django Software Foundation Django >= 6.0, < 6.0.5; >= 5.2, < 5.2.14
Timeline
- 2026-05-05: disclosed
- 2026-05-05: advisory
- 2026-05-05: patched