CVE-2026-16207

Source
https://cve.org/CVERecord?id=CVE-2026-16207
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16207.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-16207
Published
2026-07-19T02:30:08.210Z
Modified
2026-08-12T03:51:13.461511478Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
django-tastypie authentication.py ApiKeyAuthentication get request method with sensitive query strings
Details

A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthentication of the file tastypie/authentication.py. The manipulation results in use of get request method with sensitive query strings. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cwe_ids": [
        "CWE-598"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16207.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/django-tastypie/django-tastypie

Affected ranges

Type
GIT
Repo
https://github.com/django-tastypie/django-tastypie
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.15.0"
        },
        {
            "last_affected": "0.15.0"
        },
        {
            "introduced": "0.15.1"
        },
        {
            "last_affected": "0.15.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.15.0
0.15.1
v0.*
v0.15.0
v0.15.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16207.json"