Back

LOW

Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware

Published May 5, 2026

Description

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). This can lead to private data being stored and served. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmad Sadeddin for reporting this issue.

Affected products

Remediation

Red Hat mitigation

To mitigate this issue, disable the `django.middleware.cache.UpdateCacheMiddleware` in your Django application's `settings.py` file by removing it from the `MIDDLEWARE` list. This action prevents the erroneous caching of requests with an asterisk in the `Vary` header, thereby eliminating the information disclosure vulnerability. Be aware that disabling this middleware will also deactivate Django's built-in caching functionality, which may affect application performance and behavior. A restart of the Django application server is required for this change to take effect.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner DSF
Published May 5, 2026
Updated May 6, 2026
Reserved Apr 23, 2026
CISA Vulnrichment
Updated May 5, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 5, 2026
GHSA-5HRC-GVXJ-W55P