Inefficient Algorithmic Complexity in django-rest-framework - #VU153874
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity and repeated parsing without aggregate input limits in the content negotiation component when processing HTTP Accept headers. A remote attacker can send specially crafted requests containing many Accept tokens with large, semicolon-filled quoted parameter values to cause a denial of service.
The tokens must use distinct parameter names to avoid deduplication. In the reported test, two concurrent requests occupied both synchronous workers in a default two-worker deployment, preventing normal requests from being served.