Information disclosure in django-rest-framework - CVE-2026-73229
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information protected by GET permissions.
The vulnerability exists due to missing GET permission checks in AdminRenderer when rendering 400 Bad Request responses for invalid write requests. A remote user can submit an invalid write request and negotiate HTML rendering to disclose sensitive information protected by GET permissions.
AdminRenderer must be enabled, and the view must permit the write method while denying GET access. The reported testing did not identify this behavior in normal JSON rendering or successful write requests.