Sploitus

CVE-2026-35192

No indexed exploits for CVE-2026-35192 yet

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

Affected products
Django, Linuxmint, Red Os, Ubuntu
Djangoproject Django
< 5.2.14, 6.0.5
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
0.5% (43th percentile)
Weakness
CWE-539
NVD status
Analyzed
Published
2026-05-05
Attack patterns
CAPEC-60
CVE-2026-35192 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-35192 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-35192 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.