Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73228

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser for application/json and application/x-www-form-urlencoded bodies, bypassing Django's DATA_UPLOAD_MAX_MEMORY_SIZE protection and allowing oversized request bodies to consume additional memory and CPU. This issue is fixed in version 3.17.2.

A flaw was found in Django REST framework. A remote attacker could exploit a vulnerability in the request.data parsing mechanism, which bypasses Django's DATA_UPLOAD_MAX_MEMORY_SIZE protection. This allows an attacker to send oversized JSON and URL-encoded request bodies, leading to excessive consumption of memory and CPU resources. This could result in a Denial of Service (DoS) for the affected application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/controller-rhel8Out of support scope
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/eda-controller-rhel8Out of support scope
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/hub-rhel8Out of support scope
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8Out of support scope
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/controller-rhel8Out of support scope
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/eda-controller-rhel8Out of support scope
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/gateway-rhel8Out of support scope
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/hub-rhel8Out of support scope
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Out of support scope
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2514317djangorestframework: Django REST framework: Denial of Service via oversized request bodies

EPSS

Процентиль: 24%
0.00321
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
17 дней назад

Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser for application/json and application/x-www-form-urlencoded bodies, bypassing Django's DATA_UPLOAD_MAX_MEMORY_SIZE protection and allowing oversized request bodies to consume additional memory and CPU. This issue is fixed in version 3.17.2.

CVSS3: 5.3
nvd
17 дней назад

Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser for application/json and application/x-www-form-urlencoded bodies, bypassing Django's DATA_UPLOAD_MAX_MEMORY_SIZE protection and allowing oversized request bodies to consume additional memory and CPU. This issue is fixed in version 3.17.2.

CVSS3: 5.3
debian
17 дней назад

Django REST framework is a toolkit for building Web APIs. Prior to 3.1 ...

EPSS

Процентиль: 24%
0.00321
Низкий

5.3 Medium

CVSS3

Уязвимость CVE-2026-73228