← العودة للجدول
CVE-2026-35193
CVE-2026-35193 — GHSA: An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware...
📅 2026-06-03
🟢 Low 🔥 No GHSA AI Attack Vulnerability CVSS 3.1

📋 الوصف الكامل

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL. Earlier, unsupported Django series

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

AI Attack

🔗 CVE ID

CVE-2026-35193

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←