티스토리 수익 글 보기
{{ message }}
Django: has_vary_header may expose cached responses when Vary values contain whitespace
Low severity
GitHub Reviewed
Published
Jun 3, 2026
to the GitHub Advisory Database
•
Updated Aug 7, 2026
Description
Published by the National Vulnerability Database
Jun 3, 2026
Published to the GitHub Advisory Database
Jun 3, 2026
Reviewed
Aug 7, 2026
Last updated
Aug 7, 2026
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.
django.utils.cache.has_vary_header()in Django does not strip leading or trailing whitespace fromVaryresponse header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values.Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Navid Rezazadeh for reporting this issue.
References