{"id":"CVE-2026-54625","summary":"django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)","details":"django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key function includes the cache prefix, site, language, path, and timezone but not the declared header values. Although set_page_cache adds those names to the response Vary header, get_page_cache retrieves the first stored variant under the same header-agnostic key. When CMS_PAGE_CACHE is enabled and a plugin varies content on a header such as Country-Code, one visitor can receive another visitor’s request-specific content, and an unauthenticated attacker can prime the cache with attacker-chosen content. This issue is fixed in versions 5.0.8 and 5.1.0.","aliases":["GHSA-fwjf-m4qw-9f2x"],"modified":"2026-08-22T03:58:06.563272417Z","published":"2026-08-20T17:58:03.255Z","database_specific":{"cwe_ids":["CWE-349","CWE-524"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54625.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/django-cms/django-cms/releases/tag/5.0.8"},{"type":"WEB","url":"https://github.com/django-cms/django-cms/releases/tag/5.1.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54625.json"},{"type":"ADVISORY","url":"https://github.com/django-cms/django-cms/security/advisories/GHSA-fwjf-m4qw-9f2x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54625"},{"type":"FIX","url":"https://github.com/django-cms/django-cms/commit/8758714b865ffa79c6bcd0e5c503958ea48885aa"},{"type":"FIX","url":"https://github.com/django-cms/django-cms/commit/d5dc1efa18d157445491c4b12c2dd1efd56f439f"},{"type":"FIX","url":"https://github.com/django-cms/django-cms/pull/8646"},{"type":"FIX","url":"https://github.com/django-cms/django-cms/pull/8647"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/django-cms/django-cms","events":[{"introduced":"0"},{"introduced":"60e277ccda3a9434af0204d3480d34f971de3da0"},{"fixed":"6da7840759c2b345a0e2fd4e796be001e681c6a4"},{"fixed":"d399600a1c06918757c32b4f06d69118e1a7a5bf"},{"fixed":"8758714b865ffa79c6bcd0e5c503958ea48885aa"},{"fixed":"d5dc1efa18d157445491c4b12c2dd1efd56f439f"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"5.0.8"},{"introduced":"5.1.0a1"},{"fixed":"5.1.0"}]}}],"versions":["5.0.7","5.0.6","5.1.0a1","5.1.0dev1","5.0.5","5.0.4","5.0.3","5.0.2","5.0.1","5.0.0","5.0.0a1","4.0.0dev11","4.0.0","3.5.2","3.5.1","3.5.0","3.5.0rc1","3.4.2","3.4.1","3.4.0","3.4.0rc3","3.4.0rc2","3.4.0rc1","3.3.0","3.3.0.rc4","3.3.0.rc3","3.3.0.rc2","3.2.0","3.2.0.rc14","3.2.0.rc13","3.2.0.rc12","3.2.0.rc11","3.2.0.rc10","3.2.0.rc9","3.2.0.rc8","3.2.0.rc7","3.2.0.rc6","3.2.0.rc5","3.2.0.rc4","3.2.0.rc3","3.2.0.rc1","2.3.4","3.1","3.0.9","3.0.10","3.0.8","3.0.7","3.0.6","3.0.5","3.0.3","3.0.4","3.0.2","3.0.1","3.0","3.0c2","3.0c1","temporary","3.0.0.beta3","3.0.0.beta2","3.0.0.beta","2.4.1","2.4.0","2.4.0.rc1","2.3.5","2.1.4","2.2","2.3.3","show","2.3.2","2.3.2.rc1","2.3","2.3rc1","2.1.3","2.1.2","2.1.1","2.1.0","2.1.0.rc3","2.1.0.rc2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54625.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}