<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:44:19.121178+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-73228</id>
    <title>CVE-2026-73228 — Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlenco…</title>
    <updated>2026-10-03T02:44:19.153312+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> encode django-rest-framework</p>
<p>Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser for application/json and application/x-www-form-urlencoded bodies, bypassing Django's DATA_UPLOAD_MAX_MEMORY_SIZE protection and allowing oversized request bodies to consume additional memory and CPU. This issue is fixed in version 3.17.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-73228"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2m8g-3cmr-wg3w</id>
    <title>GHSA-2m8g-3cmr-wg3w — Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlenco…</title>
    <updated>2026-10-03T02:44:19.153374+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: djangorestframework</p>
<p>## Summary</p>
<p>While investigating Django REST Framework's request parsing behavior, I identified that DRF's high-level `request.data` parsing appears to bypass Django's configured `DATA_UPLOAD_MAX_MEMORY_SIZE` protection for `application/json` and `application/x-www-form-urlencoded` request bodies.</p>
<p>In the tested configurations, Django correctly raises `RequestDataTooBig` when applications access `request.body` or Django's native `request.POST`, but DRF successfully parses the same oversized payloads through `request.data`.</p>
<p>This behavior appears to occur because DRF passes the underlying `HttpRequest` object directly to parsers, which consume the request stream through Django's lower-level streaming interface rather than the guarded `request.body` path.</p>
<p>I am reporting this privately because I am unsure whether this behavior is considered part of DRF's intended security boundary, but it appears to bypass a documented Django request-size protection for common DRF request parsing paths and may have availability implications.</p>
<p># What I Verified</p>
<p>I verified the behavior locally using the following combinations:</p>
<p>* Django **6.0.7** + DRF **3.17.1** → **Affected**
* Django **6.0.7** + DRF **current upstream main** → **Affected**</p>
<p>For both versions, the observed behavior was:</p>
<p>```
Django request.body
→ RequestDataTooBig</p>
<p>Django request.POST (application/x-www-form-urlencoded)
→ RequestDataTooBig</p>
<p>Django request.read()
→ Reads the entire oversized request body</p>
<p>DRF request.data
→ Su…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2m8g-3cmr-wg3w"/>
  </entry>
</feed>
