django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through getvarycacheon(). The pagecachekey function includes the cache prefix, site, language, path, and timezone but not the declared header values. Although setpagecache adds those names to the response Vary header, getpagecache retrieves the first stored variant under the same header-agnostic key. When CMSPAGECACHE is enabled and a plugin varies content on a header such as Country-Code, one visitor can receive another visitor’s request-specific content, and an unauthenticated attacker can prime the cache with attacker-chosen content. This issue is fixed in versions 5.0.8 and 5.1.0.
{
"cwe_ids": [
"CWE-349",
"CWE-524"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54625.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "5.0.8"
},
{
"introduced": "5.1.0a1"
},
{
"fixed": "5.1.0"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}