SB20261007219 - Multiple vulnerabilities in django-rest-framework



SB20261007219 - Multiple vulnerabilities in django-rest-framework

Published: October 7, 2026

Security Bulletin ID SB20261007219
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Partial DoS

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-73228)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass Django's configured request-body size limit and increase memory and CPU consumption.

The vulnerability exists due to allocation of resources without enforcing the configured request-body size limit in Django REST Framework's request.data parsing through JSONParser and FormParser when processing JSON and URL-encoded request bodies. A remote attacker can send request bodies exceeding DATA_UPLOAD_MAX_MEMORY_SIZE to bypass Django's configured request-body size limit and increase memory and CPU consumption.

Multipart form-data parsing is not affected. The behavior was reproduced on both direct WSGI and ASGI servers.


2) Information disclosure (CVE-ID: CVE-2026-73229)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information protected by GET permissions.

The vulnerability exists due to missing GET permission checks in AdminRenderer when rendering 400 Bad Request responses for invalid write requests. A remote user can submit an invalid write request and negotiate HTML rendering to disclose sensitive information protected by GET permissions.

AdminRenderer must be enabled, and the view must permit the write method while denying GET access. The reported testing did not identify this behavior in normal JSON rendering or successful write requests.


Remediation

Install update from vendor's website.