Allocation of Resources Without Limits or Throttling in django-rest-framework - CVE-2026-73228
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass Django's configured request-body size limit and increase memory and CPU consumption.
The vulnerability exists due to allocation of resources without enforcing the configured request-body size limit in Django REST Framework's request.data parsing through JSONParser and FormParser when processing JSON and URL-encoded request bodies. A remote attacker can send request bodies exceeding DATA_UPLOAD_MAX_MEMORY_SIZE to bypass Django's configured request-body size limit and increase memory and CPU consumption.
Multipart form-data parsing is not affected. The behavior was reproduced on both direct WSGI and ASGI servers.