<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:11:35 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10003</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10003</link>
      <description>bdu:2026-10003</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10003</guid>
    </item>
    <item>
      <title>BIT-django-2026-6907 — Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware</title>
      <link>https://cve.radiocsirt.org/vuln/bit-django-2026-6907</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: django&lt;/p&gt;
&lt;p&gt;An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.
`django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`&amp;#39;*&amp;#39;`). This can lead to private data being stored and served.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Ahmad Sadeddin for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: django&lt;/p&gt;
&lt;p&gt;An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.
`django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`&amp;#39;*&amp;#39;`). This can lead to private data being stored and served.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Ahmad Sadeddin for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-django-2026-6907</guid>
    </item>
    <item>
      <title>EUVD-2026-308755</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-308755</link>
      <description>EUVD-2026-308755</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-308755</guid>
    </item>
    <item>
      <title>fkie_cve-2026-6907</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-6907</link>
      <description>&lt;p&gt;An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.
`django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`&amp;#39;*&amp;#39;`). This can lead to private data being stored and served.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Ahmad Sadeddin for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.
`django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`&amp;#39;*&amp;#39;`). This can lead to private data being stored and served.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Ahmad Sadeddin for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-6907</guid>
    </item>
    <item>
      <title>GHSA-5hrc-gvxj-w55p — Django Uses Cache Containing Sensitive Information</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5hrc-gvxj-w55p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Django&lt;/p&gt;
&lt;p&gt;An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`&amp;#39;*&amp;#39;`). This can lead to private data being stored and served. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.&lt;/p&gt;
&lt;p&gt;Django thanks Ahmad Sadeddin for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Django&lt;/p&gt;
&lt;p&gt;An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`&amp;#39;*&amp;#39;`). This can lead to private data being stored and served. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.&lt;/p&gt;
&lt;p&gt;Django thanks Ahmad Sadeddin for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5hrc-gvxj-w55p</guid>
    </item>
    <item>
      <title>OESA-2026-2217 — python-django security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2217</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: python-django&lt;/p&gt;
&lt;p&gt;A high-level Python Web framework that encourages rapid development and clean, pragmatic design.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.
`MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including excessive whitespace.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Seokchan Yoon for reporting this issue.(CVE-2026-33033)&lt;/p&gt;
&lt;p&gt;An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated Content-Length header could bypass the DATA_UPLOAD_MAX_MEMORY_SIZE limit when reading HttpRequest.body, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.(CVE-2026-33034)&lt;/p&gt;
&lt;p&gt;This issue was discovered in version 6.0, before 6.0.5, and before 5.2.14. If the session has not been modified, the cookie&amp;amp;amp;#39;s response header does not change, but &amp;amp;amp;quot;SESSION_SAVE_EVERY_REQUEST&amp;amp;amp;quot; is &amp;amp;amp;quot;true&amp;amp;amp;quot;. A remote attacker could steal a user&amp;amp;amp;#39;s session after the user visits a cached public page. Earlier unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) have not b…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: python-django&lt;/p&gt;
&lt;p&gt;A high-level Python Web framework that encourages rapid development and clean, pragmatic design.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.
`MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including excessive whitespace.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Seokchan Yoon for reporting this issue.(CVE-2026-33033)&lt;/p&gt;
&lt;p&gt;An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated Content-Length header could bypass the DATA_UPLOAD_MAX_MEMORY_SIZE limit when reading HttpRequest.body, allowing remote attackers to load an unbounded request body into memory. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Superior for reporting this issue.(CVE-2026-33034)&lt;/p&gt;
&lt;p&gt;This issue was discovered in version 6.0, before 6.0.5, and before 5.2.14. If the session has not been modified, the cookie&amp;amp;amp;#39;s response header does not change, but &amp;amp;amp;quot;SESSION_SAVE_EVERY_REQUEST&amp;amp;amp;quot; is &amp;amp;amp;quot;true&amp;amp;amp;quot;. A remote attacker could steal a user&amp;amp;amp;#39;s session after the user visits a cached public page. Earlier unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) have not b…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2217</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10708-1 — python311-Django4-4.2.30-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10708-1</link>
      <description>&lt;p&gt;python311-Django4-4.2.30-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-Django4-4.2.30-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10708-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-55</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-55</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django&lt;/p&gt;
&lt;p&gt;An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.
`django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`&amp;#39;*&amp;#39;`). This can lead to private data being stored and served.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Ahmad Sadeddin for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django&lt;/p&gt;
&lt;p&gt;An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.
`django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`&amp;#39;*&amp;#39;`). This can lead to private data being stored and served.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Ahmad Sadeddin for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-55</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:1740-1 — Security update for python-Django</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:1740-1</link>
      <description>&lt;p&gt;Security update for python-Django&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Django&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:1740-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-6907</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-6907</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-django, Ubuntu:Pro:16.04:LTS: python-django, Ubuntu:Pro:18.04:LTS: python-django, Ubuntu:Pro:20.04:LTS: python-django, Ubuntu:22.04:LTS: python-django, Ubuntu:24.04:LTS: python-django, Ubuntu:25.10: python-django, Ubuntu:26.04:LTS: python-django&lt;/p&gt;
&lt;p&gt;An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`&amp;#39;*&amp;#39;`). This can lead to private data being stored and served. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmad Sadeddin for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-django, Ubuntu:Pro:16.04:LTS: python-django, Ubuntu:Pro:18.04:LTS: python-django, Ubuntu:Pro:20.04:LTS: python-django, Ubuntu:22.04:LTS: python-django, Ubuntu:24.04:LTS: python-django, Ubuntu:25.10: python-django, Ubuntu:26.04:LTS: python-django&lt;/p&gt;
&lt;p&gt;An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`&amp;#39;*&amp;#39;`). This can lead to private data being stored and served. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmad Sadeddin for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-6907</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1373 — Django: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1373</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Django ausnutzen, um Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Django ausnutzen, um Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1373</guid>
    </item>
  </channel>
</rss>
