`django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). This can lead to private data being stored and served.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Ahmad Sadeddin for reporting this issue.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5hrc-gvxj-w55p | Django Uses Cache Containing Sensitive Information |
Ubuntu USN |
USN-8232-1 | Django vulnerabilities |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 09 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 07 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* |
Wed, 06 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Djangoproject
Djangoproject django |
|
| Vendors & Products |
Djangoproject
Djangoproject django |
Tue, 05 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). This can lead to private data being stored and served. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmad Sadeddin for reporting this issue. | |
| Title | Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware | |
| Weaknesses | CWE-524 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: DSF
Published:
Updated: 2026-05-06T15:25:33.698Z
Reserved: 2026-04-23T11:19:30.877Z
Link: CVE-2026-6907
Updated: 2026-05-05T17:03:49.787Z
Status : Analyzed
Published: 2026-05-05T16:16:18.227
Modified: 2026-05-07T14:16:04.940
Link: CVE-2026-6907
OpenCVE Enrichment
Updated: 2026-05-05T18:00:12Z
Github GHSA
Ubuntu USN