Junglewise Threat Intelligence

CVE-2026-6907: Django incorrect caching of sensitive information in UpdateCacheMiddleware

CVE-2026-6907 · Severity: medium · CVSS 4.3 · Published 2026-05-05

Technologies: Django Software Foundation Django, Django (PyPI). Vendors: Django Software Foundation, PyPI.

Executive brief

Django is a popular web framework used to build and power websites. A vulnerability in its caching system could cause the server to accidentally store and serve private, user-specific data to other visitors. This could lead to the exposure of sensitive information to unauthorized individuals.

Technical details

A vulnerability exists in Django's UpdateCacheMiddleware (CWE-524) where the middleware incorrectly caches responses even when the 'Vary' HTTP header contains an asterisk ('*'). According to HTTP standards, a 'Vary: *' header indicates that the response is uncacheable because it depends on information not present in the request headers. By caching these responses, Django may serve one user's private data to subsequent requesters. The issue affects Django versions 6.0.x before 6.0.5 and 5.2.x before 5.2.14; older unsupported versions may also be vulnerable. Patches are available in versions 6.0.5 and 5.2.14.

Affected products

  • Django Software Foundation Django >= 6.0, < 6.0.5; >= 5.2, < 5.2.14

Timeline

  • 2026-05-05: disclosed
  • 2026-05-05: advisory
  • 2026-05-05: patched

References

Related threats