---
id: CVE-2026-16212
title: A vulnerability was identified in awesto django-shop up to 1.2.4
summary: >-
  A vulnerability was identified in awesto django-shop up to 1.2.4. Affected is
  an unknown function of the file shop/models/inventory.py of the component
  Purchase Stock Handler. The manipulation leads to race condition. The attack
  is possi…
severity: medium
cvss: 4.2
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-362
published: '2026-07-19'
updated: '2026-07-19'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16212'
references:
  - url: 'https://github.com/awesto/django-shop/'
    label: cna@vuldb.com
  - url: 'https://github.com/awesto/django-shop/issues/888'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-16212'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/857939'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/380028'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/380028/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.0029
epssPercentile: 0.19213
ingestedAt: '2026-07-19T14:31:06.825Z'
---

## Overview

A vulnerability was identified in awesto django-shop up to 1.2.4. Affected is an unknown function of the file shop/models/inventory.py of the component Purchase Stock Handler. The manipulation leads to race condition. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
