CVE-2026-48587
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Navid Rezazadeh for reporting this issue.
Scoring
- Severity
- LOW
- CVSS base score
- 3.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.37%
- CWE
- CWE-1023
- Published
- 2026-06-03
- Last modified
- 2026-06-03
Affected products
- djangoproject Django
- djangoproject Django
- djangoproject Django
- djangoproject Django
Weakness type
Related vulnerabilities
- CVE-2026-81376 — Visual Studio Code Security Feature Bypass Vulnerability
- CVE-2026-14199 — Session takeover via Auth Proxy cache key collision
- CVE-2026-54713 — CakePHP Queue: Incomplete Comparison in getUniqueId vulnerable to collisions
- CVE-2026-24255 — NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an...
- CVE-2026-48761 — Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet>, <iframe>, <img> and the URL Inside <meta http-equiv="refresh"> content
- CVE-2026-53859 — OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency
- CVE-2026-53839 — OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint Validation
- CVE-2026-7473 — Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass