SB20261007220 - Multiple vulnerabilities in django-rest-framework



SB20261007220 - Multiple vulnerabilities in django-rest-framework

Published: October 7, 2026

Security Bulletin ID SB20261007220
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Inefficient Algorithmic Complexity (CVE-ID: N/A)

CWE-ID: CWE-407 - Inefficient Algorithmic Complexity

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to inefficient algorithmic complexity and repeated parsing without aggregate input limits in the content negotiation component when processing HTTP Accept headers. A remote attacker can send specially crafted requests containing many Accept tokens with large, semicolon-filled quoted parameter values to cause a denial of service.

The tokens must use distinct parameter names to avoid deduplication. In the reported test, two concurrent requests occupied both synchronous workers in a default two-worker deployment, preventing normal requests from being served.


2) Detection of Error Condition Without Action (CVE-ID: N/A)

CWE-ID: CWE-390 - Detection of error condition without action

CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to retain access using an authentication token believed to have been revoked.

The vulnerability exists due to a primary-key mismatch that silently leaves token records undeleted in TokenProxy.delete() when revoking authentication tokens through proxy instances. A remote attacker can send requests using a token that survived an attempted revocation to retain access using an authentication token believed to have been revoked.

Authentication tokens do not expire automatically. Exploitation depends on the deployment using proxy instances for token revocation; no untrusted input reaches the deletion code path.


3) Improper handling of highly compressed data (CVE-ID: N/A)

CWE-ID: CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service through excessive memory allocation.

The vulnerability exists due to improper handling of highly compressed data in JSONParser.parse when processing JSON request bodies with a client-supplied charset. A remote attacker can send a compressed request body and specify a compression codec in the Content-Type charset parameter to cause a denial of service through excessive memory allocation.

No application configuration beyond the default parser set is required.


Remediation

Install update from vendor's website.