CVE-2026-6873 Details
Description
An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and salt argument), which allows a remote attacker to use a cookie in a context different from the one where it was signed, via distinct `(name, salt)` pairs that produce the same concatenation. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Peng Zhou for reporting this issue.
A vulnerability exists in Django versions 6.0 prior to 6.0.6 and 5.2 prior to 5.2.15, in the `django.http.HttpRequest.get_signed_cookie` method. The issue arises from a non-injective salt derivation process, where the cookie name and salt argument are simply concatenated. This allows remote attackers to manipulate cookies by using different `(name, salt)` pairs that result in the same concatenation, potentially leading to unauthorized cookie acceptance in different contexts. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) may also be affected.
Users can upgrade to Django versions 6.0.6 or 5.2.15 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.djangoproject.com/en/dev/releases/security/ | Django Software Foundation | PatchVendor Advisory |
| https://groups.google.com/g/django-announce | Django Software Foundation | Release Notes |
| https://www.djangoproject.com/weblog/2026/jun/03/security-releases/ | Django Software Foundation | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | Django Software Foundation |
Affected Products
| Product | Versions |
|---|---|
| djangoproject django | >= 5.2, < 5.2.15 >= 6.0, < 6.0.6 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | Django Software Foundation |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | Initial Analysis | [email protected] |
| Jun 3, 2026 | New CVE Received | Django Software Foundation |