CVE-2026-16207
⚪ Do wiadomości
Wykorzystanie metody GET w django-tastypie pozwala na ujawnienie wrażliwych danych.
CVSS
3.7
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)
A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthentication of the file tastypie/authentication.py. The manipulation results in use of get request method with sensitive query strings. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult. The project was informed of the problem early through an issue report but has not responded yet.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 3.7 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2026-07-19 04:16:44 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-20 14:16:54 UTC |
Referencje
- https://github.com/django-tastypie/django-tastypie/ (cna@vuldb.com)
- https://github.com/django-tastypie/django-tastypie/issues/1700 (cna@vuldb.com)
- https://vuldb.com/cve/CVE-2026-16207 (cna@vuldb.com)
- https://vuldb.com/submit/857924 (cna@vuldb.com)
- https://vuldb.com/vuln/380023 (cna@vuldb.com)
- https://vuldb.com/vuln/380023/cti (cna@vuldb.com)