Improper handling of highly compressed data in django-rest-framework - #VU153876
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service through excessive memory allocation.
The vulnerability exists due to improper handling of highly compressed data in JSONParser.parse when processing JSON request bodies with a client-supplied charset. A remote attacker can send a compressed request body and specify a compression codec in the Content-Type charset parameter to cause a denial of service through excessive memory allocation.
No application configuration beyond the default parser set is required.