CVE-2026-16207 MEDIUM

CVE-2026-16207: django-tastypie authentication.py ApiKeyAuthentication get request method with sensitive query strings

Vendor N/A
Product django-tastypie
Weakness CWE-598
Published July 19, 2026
Last update July 20, 2026

CVSS base score

6.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X

What the vulnerability does

01Description

A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthentication of the file tastypie/authentication.py. The manipulation results in use of get request method with sensitive query strings. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult. The project was informed of the problem early through an issue report but has not responded yet.

Key dates

02Disclosure timeline

July 19, 2026 CVE published
July 20, 2026 Record updated