Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie
Published Jun 3, 2026
2.3
LOWCVSS 4.0
EPSS 0.28%
Description
An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and salt argument), which allows a remote attacker to use a cookie in a context different from the one where it was signed, via distinct `(name, salt)` pairs that produce the same concatenation. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Peng Zhou for reporting this issue.
Affected products
-
Affected
- ≥ 5.2, < 5.2.15
- ≥ 6.0, < 6.0.6
Unaffected
- 5.2.15
- 6.0.6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Djangoproject | Django | unaffected | Affected
Unaffected
|
- ≥ 5.2 · < 5.2.15
- ≥ 6.0 · < 6.0.6
No data.
Red Hat Ansible Automation Platform 2
ansible-automation-platform-24/lightspeed-rhel8
Fix deferred
Red Hat Ansible Automation Platform 2
ansible-automation-platform-25/lightspeed-rhel8
Fix deferred
Red Hat Ansible Automation Platform 2
ansible-automation-platform-26/controller-rhel9
Fix deferred
Red Hat Ansible Automation Platform 2
ansible-automation-platform-26/eda-controller-rhel9
Fix deferred
Red Hat Ansible Automation Platform 2
ansible-automation-platform-26/gateway-rhel9
Fix deferred
Red Hat Ansible Automation Platform 2
ansible-automation-platform-26/hub-rhel9
Fix deferred
Red Hat Ansible Automation Platform 2
ansible-automation-platform-26/lightspeed-rhel9
Fix deferred
Red Hat Ansible Automation Platform 2
ansible-automation-platform-27/aap-cloud-billing-rhel9
Fix deferred
Red Hat Ansible Automation Platform 2
ansible-automation-platform-27/controller-rhel9
Fix deferred
Red Hat Ansible Automation Platform 2
ansible-automation-platform-27/eda-controller-rhel9
Fix deferred
Red Hat Ansible Automation Platform 2
ansible-automation-platform-27/gateway-rhel9
Fix deferred
Red Hat Ansible Automation Platform 2
ansible-automation-platform-27/hub-rhel9
Fix deferred
Red Hat Ansible Automation Platform 2
ansible-automation-platform-27/lightspeed-rhel9
Fix deferred
Red Hat Ansible Automation Platform 2
ansible-automation-platform-27/metrics-service-rhel9
Fix deferred
Red Hat Ansible Automation Platform 2
ansible-automation-platform-tech-preview/metrics-service-rhel9
Fix deferred
Red Hat Ansible Automation Platform 2
ansible-automation-platform/automation-dashboard-rhel9
Fix deferred
Red Hat Ansible Automation Platform 2
automation-controller
Fix deferred
Red Hat Discovery 2
discovery/discovery-server-rhel9
Fix deferred
Red Hat Satellite 6
satellite/iop-advisor-backend-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/lightspeed-rhel8 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/lightspeed-rhel8 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/controller-rhel9 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/eda-controller-rhel9 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/gateway-rhel9 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/hub-rhel9 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/lightspeed-rhel9 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/aap-cloud-billing-rhel9 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/controller-rhel9 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/eda-controller-rhel9 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/gateway-rhel9 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/hub-rhel9 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/lightspeed-rhel9 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/metrics-service-rhel9 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-tech-preview/metrics-service-rhel9 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform/automation-dashboard-rhel9 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 2 | automation-controller | Fix deferred | n/a |
| Red Hat Discovery 2 | discovery/discovery-server-rhel9 | Fix deferred | n/a |
| Red Hat Satellite 6 | satellite/iop-advisor-backend-rhel9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (13)
- https://access.redhat.com/security/cve/CVE-2026-6873 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2484373 Issue Tracking
- https://docs.djangoproject.com/en/dev/releases/security vendor-advisoryPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34086 Advisory
- https://github.com/advisories/GHSA-h7pc-vwp9-298g Advisory
- https://github.com/django/django/commit/594360cbf58be7f56eb6da96d58644297c99ef85
- https://github.com/django/django/commit/70d36515b9cc71700105a14b275583070d48b689
- https://github.com/django/django/commit/c807d9c398022d23cb27518fa6ecaf343efb30cf
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2026-199.yaml
- https://groups.google.com/g/django-announce mailing-listRelease Notes
- https://nvd.nist.gov/vuln/detail/CVE-2026-6873
- https://www.cve.org/CVERecord?id=CVE-2026-6873
- https://www.djangoproject.com/weblog/2026/jun/03/security-releases vendor-advisoryPatchVendor Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub