Information disclosure in django-rest-framework - CVE-2026-73229

 

Information disclosure in django-rest-framework - CVE-2026-73229

Published: October 7, 2026


Vulnerability identifier: #VU153873
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-73229
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information protected by GET permissions.

The vulnerability exists due to missing GET permission checks in AdminRenderer when rendering 400 Bad Request responses for invalid write requests. A remote user can submit an invalid write request and negotiate HTML rendering to disclose sensitive information protected by GET permissions.

AdminRenderer must be enabled, and the view must permit the write method while denying GET access. The reported testing did not identify this behavior in normal JSON rendering or successful write requests.


Affected software

django-rest-framework

How to mitigate CVE-2026-73229

Install security update from vendor's website.

django-rest-framework - update to 3.17.1

External References

Related Security Bulletins