CVE-2026-8404
published 2026-06-03CVE-2026-8404: An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match…
PriorityP433medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.29%
20.1th percentile
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.
`django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Ahmed Badawe for reporting this issue.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-24 | lightspeed-rhel8 | — | — |
| ansible-automation-platform-25 | lightspeed-rhel8 | — | — |
| ansible-automation-platform-26 | controller-rhel9 | — | — |
| ansible-automation-platform-26 | eda-controller-rhel9 | — | — |
| ansible-automation-platform-26 | gateway-rhel9 | — | — |
| ansible-automation-platform-26 | hub-rhel9 | — | — |
| ansible-automation-platform-26 | lightspeed-rhel9 | — | — |
| ansible-automation-platform-27 | aap-cloud-billing-rhel9 | — | — |
| ansible-automation-platform-27 | controller-rhel9 | — | — |
| ansible-automation-platform-27 | eda-controller-rhel9 | — | — |
| ansible-automation-platform-27 | gateway-rhel9 | — | — |
| ansible-automation-platform-27 | hub-rhel9 | — | — |
| ansible-automation-platform-27 | lightspeed-rhel9 | — | — |
| ansible-automation-platform-27 | metrics-service-rhel9 | — | — |
| ansible-automation-platform-tech-preview | metrics-service-rhel9 | — | — |
| ansible-automation-platform | automation-dashboard-rhel9 | — | — |
| discovery | discovery-server-rhel9 | — | — |
| djangoproject | django | >= 5.2 < 5.2.15 | 5.2.15 |
| djangoproject | django | >= 6.0 < 6.0.6 | 6.0.6 |
| satellite | iop-advisor-backend-rhel9 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv4.02.3LOWCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat2.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Django up to 5.2.14/6.0.5 django.middleware.cache.UpdateCacheMiddleware case sensitivity (WID-SEC-2026-1807)
vuldb·2026-06-08·CVSS 5.3
CVE-2026-8404 [MEDIUM] Django up to 5.2.14/6.0.5 django.middleware.cache.UpdateCacheMiddleware case sensitivity (WID-SEC-2026-1807)
A vulnerability classified as problematic was found in Django up to 5.2.14/6.0.5. This issue affects some unknown processing of the component django.middleware.cache.UpdateCacheMiddleware. The manipulation results in improper handling of case sensitivity.
This vulnerability is known as CVE-2026-8404. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
GHSA
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.
ghsa_unreviewed·2026-06-03
CVE-2026-8404 [LOW] CWE-178 An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.
`django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Ahmed Badawe for reporting this issue.
Red Hat
Django: Django: Information disclosure due to improper handling of Cache-Control directives
vendor_redhat·2026-06-03·CVSS 2.3
CVE-2026-8404 [LOW] CWE-1289 Django: Django: Information disclosure due to improper handling of Cache-Control directives
Django: Django: Information disclosure due to improper handling of Cache-Control directives
A flaw was found in Django. The `django.middleware.cache.UpdateCacheMiddleware` component does not correctly process `Cache-Control` response directives when they use uppercase or mixed-case values. This vulnerability allows a remote attacker to read responses that should not have been cached, leading to information disclosure.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: ansible-automation-platform-24/lightspeed-rhel8 (Red Hat Ansible Automation Platform 2) - Fix deferred
Package: ansible
No detection rules found.
No public exploits indexed.
2026-06-03
Published