SB20261007219 - Multiple vulnerabilities in django-rest-framework
Published: October 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-73228)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass Django's configured request-body size limit and increase memory and CPU consumption.
The vulnerability exists due to allocation of resources without enforcing the configured request-body size limit in Django REST Framework's request.data parsing through JSONParser and FormParser when processing JSON and URL-encoded request bodies. A remote attacker can send request bodies exceeding DATA_UPLOAD_MAX_MEMORY_SIZE to bypass Django's configured request-body size limit and increase memory and CPU consumption.
Multipart form-data parsing is not affected. The behavior was reproduced on both direct WSGI and ASGI servers.
2) Information disclosure (CVE-ID: CVE-2026-73229)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information protected by GET permissions.
The vulnerability exists due to missing GET permission checks in AdminRenderer when rendering 400 Bad Request responses for invalid write requests. A remote user can submit an invalid write request and negotiate HTML rendering to disclose sensitive information protected by GET permissions.
AdminRenderer must be enabled, and the view must permit the write method while denying GET access. The reported testing did not identify this behavior in normal JSON rendering or successful write requests.
Remediation
Install update from vendor's website.