UNKNOWN PyPI
Django Uses Persistent Cookies Containing Sensitive Information
GHSA-7h2m-m8vj-598h · BIT-django-2026-35192 · CVE-2026-35192 · PYSEC-2026-50
Published · Modified
Description
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but SESSION_SAVE_EVERY_REQUEST is True. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django thanks Cantina for reporting this issue.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-35192
- WEB https://docs.djangoproject.com/en/dev/releases/security
- PACKAGE https://github.com/django/django
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2026-50.yaml
- WEB https://groups.google.com/g/django-announce
- WEB https://www.djangoproject.com/weblog/2026/may/05/security-releases
Ready to move
Start Securing
Free, no credit card | First findings in minutes