CVE-2026-73228: Encode Django-Rest-Framework

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser for application/json and application/x-www-form-urlencoded bodies, bypassing Django's DATA_UPLOAD_MAX_MEMORY_SIZE protection and allowing oversized request bodies to consume additional memory and CPU. This issue is fixed in version 3.17.2.

Affected products

  • Encode Django-Rest-Framework: before 3.17.2 (fixed in 3.17.2)

Published 2026-08-11. Last modified 2026-09-11.