CVE-2026-35192CWE-539

Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST

Low · published May 5, 2026

CVSS v4.0
2.3
EPSS
1%
Percentile
43.7
In the wild
Unconfirmed
What it is

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14.

Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page.

Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.

Django would like to thank Cantina for reporting this issue.

The record
Technical detail
CVSS v4.0
2.3 · LOW
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00544 · 43.7th percentile
Weakness
CWE-539 · Use of Persistent Cookies Containing Sensitive Information
Published
2026-05-05T14:50Z
EPSS history
Timeline
  • 05 MAY 14:50Z
    Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST
    cvelistv5