<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 20:47:12 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-54625 — django CMS: Page cache ignores plugin-declared Vary headers (disclosure &amp; poisoning)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-54625</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; django-cms&lt;/p&gt;
&lt;p&gt;django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key function includes the cache prefix, site, language, path, and timezone but not the declared header values. Although set_page_cache adds those names to the response Vary header, get_page_cache retrieves the first stored variant under the same header-agnostic key. When CMS_PAGE_CACHE is enabled and a plugin varies content on a header such as Country-Code, one visitor can receive another visitor’s request-specific content, and an unauthenticated attacker can prime the cache with attacker-chosen content. This issue is fixed in versions 5.0.8 and 5.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; django-cms&lt;/p&gt;
&lt;p&gt;django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key function includes the cache prefix, site, language, path, and timezone but not the declared header values. Although set_page_cache adds those names to the response Vary header, get_page_cache retrieves the first stored variant under the same header-agnostic key. When CMS_PAGE_CACHE is enabled and a plugin varies content on a header such as Country-Code, one visitor can receive another visitor’s request-specific content, and an unauthenticated attacker can prime the cache with attacker-chosen content. This issue is fixed in versions 5.0.8 and 5.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-54625</guid>
    </item>
    <item>
      <title>GHSA-fwjf-m4qw-9f2x — django CMS: Page cache ignores plugin-declared Vary headers (disclosure &amp; poisoning)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fwjf-m4qw-9f2x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django-cms&lt;/p&gt;
&lt;p&gt;### Summary
The CMS page cache key ignores the request headers that plugins declare via `get_vary_cache_on()`. The header is added to the response `Vary` header, but the CMS&amp;#39;s own cache key does not incorporate the header values, so the first visitor&amp;#39;s variant is served to all subsequent visitors regardless of their header values.&lt;/p&gt;
&lt;p&gt;### Details
`_page_cache_key` (in `cms/cache/page.py`) keys only on cache prefix, site, language, path and timezone. `set_page_cache` collects the plugin-declared vary headers and calls `patch_vary_headers(response, ...)` (affecting only the emitted `Vary` header), but stores and retrieves the cached page under the header-agnostic key. `get_page_cache` therefore returns whichever variant was cached first.&lt;/p&gt;
&lt;p&gt;### Impact
- **Information disclosure:** when a plugin varies its output on a request  header (e.g. `Country-Code`), the variant rendered for the first anonymous visitor is served to everyone until the entry expires, leaking request-specific content across users.
- **Cache poisoning:** an unauthenticated attacker can prime the anonymous page cache with content rendered from attacker-chosen header values, which is then served to subsequent visitors.&lt;/p&gt;
&lt;p&gt;Applies only when `CMS_PAGE_CACHE` is enabled and at least one plugin implements `get_vary_cache_on()`.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in 5.0.8: the page cache now folds the request&amp;#39;s values implements `get_vary_cache_on()`.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in 5.0.8: the page cache now folds the request&amp;#39;s values for plugin-de…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django-cms&lt;/p&gt;
&lt;p&gt;### Summary
The CMS page cache key ignores the request headers that plugins declare via `get_vary_cache_on()`. The header is added to the response `Vary` header, but the CMS&amp;#39;s own cache key does not incorporate the header values, so the first visitor&amp;#39;s variant is served to all subsequent visitors regardless of their header values.&lt;/p&gt;
&lt;p&gt;### Details
`_page_cache_key` (in `cms/cache/page.py`) keys only on cache prefix, site, language, path and timezone. `set_page_cache` collects the plugin-declared vary headers and calls `patch_vary_headers(response, ...)` (affecting only the emitted `Vary` header), but stores and retrieves the cached page under the header-agnostic key. `get_page_cache` therefore returns whichever variant was cached first.&lt;/p&gt;
&lt;p&gt;### Impact
- **Information disclosure:** when a plugin varies its output on a request  header (e.g. `Country-Code`), the variant rendered for the first anonymous visitor is served to everyone until the entry expires, leaking request-specific content across users.
- **Cache poisoning:** an unauthenticated attacker can prime the anonymous page cache with content rendered from attacker-chosen header values, which is then served to subsequent visitors.&lt;/p&gt;
&lt;p&gt;Applies only when `CMS_PAGE_CACHE` is enabled and at least one plugin implements `get_vary_cache_on()`.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in 5.0.8: the page cache now folds the request&amp;#39;s values implements `get_vary_cache_on()`.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in 5.0.8: the page cache now folds the request&amp;#39;s values for plugin-de…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fwjf-m4qw-9f2x</guid>
    </item>
  </channel>
</rss>
