SB20261007220 - Multiple vulnerabilities in django-rest-framework
Published: October 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Inefficient Algorithmic Complexity (CVE-ID: N/A)
CWE-ID: CWE-407 - Inefficient Algorithmic Complexity
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity and repeated parsing without aggregate input limits in the content negotiation component when processing HTTP Accept headers. A remote attacker can send specially crafted requests containing many Accept tokens with large, semicolon-filled quoted parameter values to cause a denial of service.
The tokens must use distinct parameter names to avoid deduplication. In the reported test, two concurrent requests occupied both synchronous workers in a default two-worker deployment, preventing normal requests from being served.
2) Detection of Error Condition Without Action (CVE-ID: N/A)
CWE-ID: CWE-390 - Detection of error condition without action
CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to retain access using an authentication token believed to have been revoked.
The vulnerability exists due to a primary-key mismatch that silently leaves token records undeleted in TokenProxy.delete() when revoking authentication tokens through proxy instances. A remote attacker can send requests using a token that survived an attempted revocation to retain access using an authentication token believed to have been revoked.
Authentication tokens do not expire automatically. Exploitation depends on the deployment using proxy instances for token revocation; no untrusted input reaches the deletion code path.
3) Improper handling of highly compressed data (CVE-ID: N/A)
CWE-ID: CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service through excessive memory allocation.
The vulnerability exists due to improper handling of highly compressed data in JSONParser.parse when processing JSON request bodies with a client-supplied charset. A remote attacker can send a compressed request body and specify a compression codec in the Content-Type charset parameter to cause a denial of service through excessive memory allocation.
No application configuration beyond the default parser set is required.
Remediation
Install update from vendor's website.