djangoproject django是djangoproject基金会开源的一个Web应用开发框架。 Django 6.0.7之前版本和5.2.16之前版本存在日志信息泄露漏洞,该漏洞源于UpdateCacheMiddleware和cache_page()装饰器在传入请求携带无关cookie时缓存基于cookie变化的响应,导致远程攻击者从共享缓存中读取私有数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| djangoproject | Django | 6.0< 6.0.7 |
affected |
6.0.7 |
unaffected | ||
5.2< 5.2.16 |
affected | ||
5.2.16 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| djangoproject | Django | 6.0 ~ 6.0.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53878 | 6.1 MEDIUM | Header injection possibility since DomainNameValidator accepted newlines in input |
| CVE-2026-53877 | 4.8 MEDIUM | Heap buffer over-read in GDALRaster |
No comments yet