Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping.
"https://github.com/pypa/advisory-database/blob/main/vulns/django-rest-framework/PYSEC-2026-804.yaml"