CVE-2026-73229: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in encode django-rest-framework
Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and directly invokes view.get() without view.check_permissions() while rendering an invalid write request, allowing a 400 Bad Request HTML response to disclose data from a GET representation that the requester is not permitted to access. This issue is fixed in version 3.17.2.
AI Analysis
Technical Summary
Django REST Framework versions before 3.17.2 contain a CWE-200 vulnerability where the AdminRenderer.render() method uses override_method() to simulate a GET request and directly invokes view.get() without performing permission checks via view.check_permissions(). This occurs during the rendering of an invalid write request, resulting in a 400 Bad Request response that discloses data from a GET representation that the requester is unauthorized to access. The vulnerability allows unauthorized actors with limited privileges to gain access to sensitive information. The issue is resolved in version 3.17.2.
Potential Impact
An attacker with limited privileges can cause the server to respond with a 400 Bad Request HTML page that includes sensitive data from a GET request representation that they are not authorized to view. This leads to unauthorized information disclosure without affecting data integrity or availability.
Mitigation Recommendations
Upgrade to Django REST Framework version 3.17.2 or later, where this vulnerability is fixed. No other mitigation or temporary workaround is indicated.
CVE-2026-73229: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in encode django-rest-framework
Description
Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and directly invokes view.get() without view.check_permissions() while rendering an invalid write request, allowing a 400 Bad Request HTML response to disclose data from a GET representation that the requester is not permitted to access. This issue is fixed in version 3.17.2.
CVSS v3.1
Score 4.3medium
Affected software
encode
django-rest-framework
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Django REST Framework versions before 3.17.2 contain a CWE-200 vulnerability where the AdminRenderer.render() method uses override_method() to simulate a GET request and directly invokes view.get() without performing permission checks via view.check_permissions(). This occurs during the rendering of an invalid write request, resulting in a 400 Bad Request response that discloses data from a GET representation that the requester is unauthorized to access. The vulnerability allows unauthorized actors with limited privileges to gain access to sensitive information. The issue is resolved in version 3.17.2.
Potential Impact
An attacker with limited privileges can cause the server to respond with a 400 Bad Request HTML page that includes sensitive data from a GET request representation that they are not authorized to view. This leads to unauthorized information disclosure without affecting data integrity or availability.
Mitigation Recommendations
Upgrade to Django REST Framework version 3.17.2 or later, where this vulnerability is fixed. No other mitigation or temporary workaround is indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-11T14:41:20.122Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7b77a2bf8831d5394b40c4
Added to database: 08/11/2026, 19:27:30 UTC
Last enriched: 08/11/2026, 19:42:50 UTC
Last updated: 09/24/2026, 13:47:48 UTC
Views: 58
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.