Back

LOW

Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie

Published Jun 3, 2026

Description

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and salt argument), which allows a remote attacker to use a cookie in a context different from the one where it was signed, via distinct `(name, salt)` pairs that produce the same concatenation. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Peng Zhou for reporting this issue.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (2)

References (13)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner DSF
Published Jun 3, 2026
Updated Jun 3, 2026
Reserved Apr 22, 2026

CISA Vulnrichment

Updated Jun 3, 2026

NVD

Status Analyzed
Modified Jul 21, 2026

Red Hat

Severity Low
Public date Jun 3, 2026
Bugzilla 2484373

ENISA EUVD

Assigner DSF
Published Jun 3, 2026
Updated Jun 3, 2026