{"id":"PYSEC-2026-629","summary":"Django Improper Access Control","details":"The LazyUser class in the AuthenticationMiddleware for Django 0.95 does not properly cache the user name across requests, which allows remote authenticated users to gain the privileges of a different user.","aliases":["CVE-2007-0405","GHSA-mwv2-398h-v489"],"modified":"2026-07-06T08:00:11.820294769Z","published":"2026-07-02T14:13:19.912742Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0405"},{"type":"WEB","url":"https://github.com/django/django/commit/3c5782287e"},{"type":"WEB","url":"https://github.com/django/django/commit/e89f0a65581f82a5740bfe989136cea75d09cd67"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31628"},{"type":"PACKAGE","url":"https://github.com/django/django"},{"type":"WEB","url":"http://code.djangoproject.com/changeset/3754"},{"type":"PACKAGE","url":"https://pypi.org/project/django"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mwv2-398h-v489"}],"affected":[{"package":{"name":"django","ecosystem":"PyPI","purl":"pkg:pypi/django"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.95"},{"fixed":"1.0"}]}],"versions":["0.95"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/django/PYSEC-2026-629.yaml"}}],"schema_version":"1.7.5"}