{"id":"CVE-2026-8404","aliases":["BIT-django-2026-8404","GHSA-8cjm-8mp7-r2xf","PYSEC-2026-201"],"url":"https://o3.security/vulnerability/CVE-2026-8404","summary":"Potential exposure of private data via case-sensitive Cache-Control directives in UpdateCacheMiddleware","details":"An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.\n`django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Ahmed Badawe for reporting this issue.","published":"2026-06-03T13:16:29.593Z","modified":"2026-08-12T03:51:12.468316417Z","cvss":null,"epss":{"score":0.00285,"percentile":0.21084,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"django","fixedVersion":"5.2.15"},{"ecosystem":"PyPI","name":"django","fixedVersion":"6.0.6"}],"fix":{"url":"https://github.com/django/django/commit/366d9ae6e8d1469c04e9ebdc1bcd098fc14a3b1e","label":"django/django@366d9ae"},"references":[{"type":"WEB","url":"https://github.com/django/django/"},{"type":"ADVISORY","url":"https://docs.djangoproject.com/en/dev/releases/security/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8404.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8404"},{"type":"ADVISORY","url":"https://www.djangoproject.com/weblog/2026/jun/03/security-releases/"},{"type":"PACKAGE","url":"https://pypi.org/project/Django/"},{"type":"ARTICLE","url":"https://groups.google.com/g/django-announce"},{"type":"WEB","url":"https://github.com/django/django/commit/366d9ae6e8d1469c04e9ebdc1bcd098fc14a3b1e"},{"type":"WEB","url":"https://github.com/django/django/commit/b4330259ffbe1a031ed14daab1f35697460f10f2"},{"type":"WEB","url":"https://github.com/django/django/commit/d618d7ae4fec727d5b582bd24f803c28d17bf7cd"},{"type":"WEB","url":"https://docs.djangoproject.com/en/dev/releases/security"},{"type":"PACKAGE","url":"https://github.com/django/django"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2026-201.yaml"},{"type":"WEB","url":"https://www.djangoproject.com/weblog/2026/jun/03/security-releases"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.468316417Z"}}