CVE-2026-35192
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.
Scoring
- Severity
- LOW
- CVSS base score
- 2.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.54%
- CWE
- CWE-539
- Published
- 2026-05-05
- Last modified
- 2026-05-06
Affected products
- djangoproject Django
- djangoproject Django
- djangoproject Django
- djangoproject Django
Weakness type
Related vulnerabilities
- CVE-2026-24318 — Insecure Session Management vulnerability in SAP BusinessObjects Business Intelligence Platform
- CVE-2025-52633 — HCL AION is susceptible to Missing Content-Security-Policy
- CVE-2024-39275 — Advantech ADAM-5630 Use of Persistent Cookies Containing Sensitive Information
- CVE-2023-30861 — Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
- CVE-2021-27463 — A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer....