CVE-2026-73228: Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`

Published Aug 11, 2026
·
Updated

Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in restframework/request.py Request.parse() passes the underlying HttpRequest stream to JSONParser and FormParser for application/json and application/x-www-form-urlencoded bodies, bypassing Django's DATAUPLOADMAXMEMORYSIZE protection and allowing oversized request bodies to consume additional memory and CPU. This issue is fixed in version 3.17.2.

Affected Software

1 affected component
Django REST framework Django REST framework<3.17.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade django-rest-framework to a version that resolves this vulnerability.

    Fixed in 3.17.2

Event History

Aug 11, 2026
CVE Published
via MITRE·06:54 PM
Data Sourced
via MITRE·06:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:18 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-73228?

CVE-2026-73228 has a medium severity rating of 5.3.

2

What risk does CVE-2026-73228 pose?

CVE-2026-73228 poses a risk level of 27, indicating potential vulnerabilities in request body parsing.

3

How can I fix CVE-2026-73228?

To fix CVE-2026-73228, update your Django REST framework to version 3.17.2 or later.

4

What types of request bodies are affected by CVE-2026-73228?

CVE-2026-73228 affects the parsing of oversized JSON and application/x-www-form-urlencoded request bodies.

5

What is the impact of CVE-2026-73228 on application security?

CVE-2026-73228 may allow attackers to bypass the DATA_UPLOAD_MAX_MEMORY_SIZE limit in Django REST framework.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203