Detection of Error Condition Without Action in django-rest-framework - #VU153875
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to retain access using an authentication token believed to have been revoked.
The vulnerability exists due to a primary-key mismatch that silently leaves token records undeleted in TokenProxy.delete() when revoking authentication tokens through proxy instances. A remote attacker can send requests using a token that survived an attempted revocation to retain access using an authentication token believed to have been revoked.
Authentication tokens do not expire automatically. Exploitation depends on the deployment using proxy instances for token revocation; no untrusted input reaches the deletion code path.