THREAT OPS › Threat News › [GHSA] GHSA-fwjf-m4qw-9f2x (medium) — django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
[GHSA] GHSA-fwjf-m4qw-9f2x (medium) — django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
GHSA-fwjf-m4qw-9f2x Severity: medium CVE: CVE-2026-54625
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
### Summary The CMS page cache key ignores the request headers that plugins declare via `get_vary_cache_on()`. The header is added to the response `Vary` header, but the CMS's own cache key does not incorporate the header values, so the first visitor's var
Indicators of compromise
- CVE-2026-54625cve
Original source: https://github.com/advisories/GHSA-fwjf-m4qw-9f2x