{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-35192","assignerOrgId":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92","state":"PUBLISHED","assignerShortName":"DSF","dateReserved":"2026-04-01T18:21:23.779Z","datePublished":"2026-05-05T14:50:29.984Z","dateUpdated":"2026-05-06T15:25:28.432Z"},"containers":{"cna":{"providerMetadata":{"orgId":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92","shortName":"DSF","dateUpdated":"2026-05-05T14:50:29.984Z"},"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-539","description":"CWE-539: Use of Persistent Cookies Containing Sensitive Information","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-60","descriptions":[{"lang":"en","value":"CAPEC-60: Reusing Session IDs (aka Session Replay)"}]}],"title":"Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST","metrics":[{"other":{"content":{"value":"low","namespace":"https://docs.djangoproject.com/en/dev/internals/security/#security-issue-severity-levels"},"type":"Django severity rating"}},{"cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","baseScore":2.3,"baseSeverity":"LOW"}}],"descriptions":[{"lang":"en","value":"An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.\nResponse headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Cantina for reporting this issue.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.</p><p>Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user&#x27;s session after that user visits a cached public page.</p><p>Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.</p><p>Django would like to thank Cantina for reporting this issue.</p>"}]}],"affected":[{"collectionURL":"https://pypi.org/project/Django/","defaultStatus":"unaffected","packageName":"django","product":"Django","repo":"https://github.com/django/django/","vendor":"djangoproject","versions":[{"status":"affected","version":"6.0","lessThan":"6.0.5","versionType":"python"},{"status":"unaffected","version":"6.0.5","versionType":"python"},{"status":"affected","version":"5.2","lessThan":"5.2.14","versionType":"python"},{"status":"unaffected","version":"5.2.14","versionType":"python"}]}],"references":[{"url":"https://docs.djangoproject.com/en/dev/releases/security/","name":"Django security archive","tags":["vendor-advisory"]},{"url":"https://groups.google.com/g/django-announce","name":"Django releases announcements","tags":["mailing-list"]},{"url":"https://www.djangoproject.com/weblog/2026/may/05/security-releases/","name":"Django security releases issued: 6.0.5 and 5.2.14","tags":["vendor-advisory"]}],"credits":[{"lang":"en","type":"reporter","value":"Cantina"},{"lang":"en","type":"remediation developer","value":"Jake Howard"},{"lang":"en","type":"coordinator","value":"Sarah Boyce"}],"timeline":[{"lang":"en","time":"2026-03-11T10:54:40.000Z","value":"Initial report received."},{"lang":"en","time":"2026-04-01T10:54:43.000Z","value":"Vulnerability confirmed."},{"lang":"en","time":"2026-05-05T09:00:00.000Z","value":"Security release issued."}],"datePublic":"2026-05-05T09:00:00.000Z","source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-05-05T17:04:02.535125Z","id":"CVE-2026-35192","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-05-06T15:25:28.432Z"}}]}}