Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-73228

MEDIUM NVD
CVSS Score 5.3
Severity MEDIUM
Published Aug 11, 2026
Vendor unknown

Description

Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser for application/json and application/x-www-form-urlencoded bodies, bypassing Django's DATA_UPLOAD_MAX_MEMORY_SIZE protection and allowing oversized request bodies to consume additional memory and CPU. This issue is fixed in version 3.17.2.

References