Detection of Error Condition Without Action in django-rest-framework - #VU153875

 

Detection of Error Condition Without Action in django-rest-framework - #VU153875

Published: October 7, 2026


Vulnerability identifier: #VU153875
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-390
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to retain access using an authentication token believed to have been revoked.

The vulnerability exists due to a primary-key mismatch that silently leaves token records undeleted in TokenProxy.delete() when revoking authentication tokens through proxy instances. A remote attacker can send requests using a token that survived an attempted revocation to retain access using an authentication token believed to have been revoked.

Authentication tokens do not expire automatically. Exploitation depends on the deployment using proxy instances for token revocation; no untrusted input reaches the deletion code path.


Affected software

django-rest-framework

Remediation

Install security update from vendor's website.

django-rest-framework - update to 3.18.2

External References

Related Security Bulletins