← العودة للجدول
CVE-2026-6873
CVE-2026-6873 — VulnCheck: An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.
📅 2026-06-03
🟢 Low 🔥 No VulnCheck Exploit Vulnerability CVSS 3.1

📋 الوصف الكامل

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and salt argument), which allows a remote attacker to use a cookie in a context different from the one where it was signed, via distinct `(name, salt)` pairs that produce the same concatenation. Earlier,

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-6873

📡 المصدر

VulnCheck

✅ الحلول والتخفيف

Refer to CVE-2026-6873 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←