CVE-2026-16208

Source
https://cve.org/CVERecord?id=CVE-2026-16208
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16208.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-16208
Published
2026-07-19T02:45:09.240Z
Modified
2026-07-20T03:46:10.569678983Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
django-tastypie throttle.py CacheDBThrottle race condition
Details

A flaw has been found in django-tastypie up to 0.15.1. The affected element is the function CacheThrottle/CacheDBThrottle of the file tastypie/throttle.py. This manipulation causes race condition. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitability is described as difficult. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16208.json",
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-362"
    ]
}
References

Affected packages

Git / github.com/django-tastypie/django-tastypie

Affected ranges

Type
GIT
Repo
https://github.com/django-tastypie/django-tastypie
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0.15.0"
        },
        {
            "last_affected": "0.15.0"
        },
        {
            "introduced": "0.15.1"
        },
        {
            "last_affected": "0.15.1"
        }
    ]
}

Affected versions

0.*
0.15.0
0.15.1
v0.*
v0.15.0
v0.15.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16208.json"