djangorestframework vulnerabilities
CVEs whose affected-version data names the djangorestframework package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-73229Medium· 4.3Django REST framework is a powerful and flexible toolkit for building Web APIs
Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and directly invokes view.…
▾ Sunlitdjangorestframework · djangorestframeworkEPSS 0.34%via NVD
CVE-2026-73228Medium· 5.3Django REST framework is a toolkit for building Web APIs
Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser f…
▾ Sunlitdjangorestframework · djangorestframeworkEPSS 0.39%via NVD
CVE-2024-21520Medium· 6.1PoCCross-site Scripting in djangorestframework
Cross-site Scripting in djangorestframework
▾ Twilightdjangorestframework · djangorestframeworkEPSS 1.1%via OSV