{"id":"CVE-2026-73229","aliases":["GHSA-g47c-3xmw-q6m2"],"url":"https://o3.security/vulnerability/CVE-2026-73229","summary":"Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests","details":"Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and directly invokes view.get() without view.check_permissions() while rendering an invalid write request, allowing a 400 Bad Request HTML response to disclose data from a GET representation that the requester is not permitted to access. This issue is fixed in version 3.17.2.","published":"2026-08-11T18:59:34.151Z","modified":"2026-08-13T04:03:02.193534919Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"djangorestframework","fixedVersion":"3.17.2"}],"fix":{"url":"https://github.com/encode/django-rest-framework/commit/71f81946906e52f9dc8e5d22a0f3d2afa50c455e","label":"encode/django-rest-framework@71f8194"},"references":[{"type":"WEB","url":"https://github.com/encode/django-rest-framework/releases/tag/3.17.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73229.json"},{"type":"ADVISORY","url":"https://github.com/encode/django-rest-framework/security/advisories/GHSA-g47c-3xmw-q6m2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73229"},{"type":"FIX","url":"https://github.com/encode/django-rest-framework/commit/71f81946906e52f9dc8e5d22a0f3d2afa50c455e"},{"type":"FIX","url":"https://github.com/encode/django-rest-framework/commit/9e82afc98acfe6fc28c9bf78147f0c5b3f222cb5"},{"type":"FIX","url":"https://github.com/encode/django-rest-framework/pull/10012"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-13T04:03:02.193534919Z"}}