CVE-2026-35192
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.
- Djangoproject Django
- < 5.2.14, 6.0.5
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.5% (43th percentile)
- Weakness
- CWE-539
- NVD status
- Analyzed
- Published
- 2026-05-05
- Attack patterns
- CAPEC-60
CVE-2026-35192 at NVD
No indexed exploits for CVE-2026-35192 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-35192 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.