Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary
Low severity
GitHub Reviewed
Published
Jun 3, 2026
to the GitHub Advisory Database
•
Updated Aug 7, 2026
Package
Affected versions
>= 5.2.0, < 5.2.15
>= 6.0.0, < 6.0.6
Patched versions
5.2.15
6.0.6
Description
Published by the National Vulnerability Database
Jun 3, 2026
Published to the GitHub Advisory Database
Jun 3, 2026
Reviewed
Aug 7, 2026
Last updated
Aug 7, 2026
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.
django.middleware.cache.UpdateCacheMiddlewarein Django does not addAuthorizationto theVaryresponse header for requests bearing that header withoutCache-Control: public, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL.Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Shai Berger for reporting this issue.
References