Bug 2502153 (CVE-2026-16207) - CVE-2026-16207 django-tastypie: ApiKeyAuthentication accepts credentials from URL parameters and CacheThrottle can be bypassed with concurrent requests
Summary: CVE-2026-16207 django-tastypie: ApiKeyAuthentication accepts credentials from...
Keywords:
Status: NEW
Alias: CVE-2026-16207
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2502780 2502781
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-19 04:01 UTC by OSIDB Bzimport
Modified: 2026-07-20 13:04 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-19 04:01:29 UTC
A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthentication of the file tastypie/authentication.py. The manipulation results in use of get request method with sensitive query strings. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult. The project was informed of the problem early through an issue report but has not responded yet.


Note You need to log in before you can comment on or make changes to this bug.