CVE-2026-54625: Django-CMS
Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.
django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key function includes the cache prefix, site, language, path, and timezone but not the declared header values. Although set_page_cache adds those names to the response Vary header, get_page_cache retrieves the first stored variant under the same header-agnostic key. When CMS_PAGE_CACHE is enabled and a plugin varies content on a header such as Country-Code, one visitor can receive another visitor’s request-specific content, and an unauthenticated attacker can prime the cache with attacker-chosen content. This issue is fixed in versions 5.0.8 and 5.1.0.
Affected products
- Django-CMS Django-CMS: before 5.0.8 (fixed in 5.0.8); from 5.1.0a1, before 5.1.0 (fixed in 5.1.0)
Published 2026-08-20. Last modified 2026-09-18.