No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 20 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Django-cms
Django-cms django Cms |
|
| Vendors & Products |
Django-cms
Django-cms django Cms |
Thu, 20 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key function includes the cache prefix, site, language, path, and timezone but not the declared header values. Although set_page_cache adds those names to the response Vary header, get_page_cache retrieves the first stored variant under the same header-agnostic key. When CMS_PAGE_CACHE is enabled and a plugin varies content on a header such as Country-Code, one visitor can receive another visitor’s request-specific content, and an unauthenticated attacker can prime the cache with attacker-chosen content. This issue is fixed in versions 5.0.8 and 5.1.0. | |
| Title | django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning) | |
| Weaknesses | CWE-349 CWE-524 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-20T19:45:17.403Z
Reserved: 2026-06-15T20:07:02.185Z
Link: CVE-2026-54625
Updated: 2026-08-20T19:45:11.491Z
Status : Received
Published: 2026-08-20T18:16:28.170
Modified: 2026-08-20T20:17:35.133
Link: CVE-2026-54625
No data.
OpenCVE Enrichment
Updated: 2026-08-20T21:00:05Z