THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fwjf-m4qw-9f2x (medium) — django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

[GHSA] GHSA-fwjf-m4qw-9f2x (medium) — django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

medgithub_advisoriesPublished 2026-08-24

GHSA-fwjf-m4qw-9f2x Severity: medium CVE: CVE-2026-54625

django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

### Summary The CMS page cache key ignores the request headers that plugins declare via `get_vary_cache_on()`. The header is added to the response `Vary` header, but the CMS's own cache key does not incorporate the header values, so the first visitor's var

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fwjf-m4qw-9f2x