CVE-2026-73229 is a vulnerability in Django REST framework that allows data disclosure through a 400 Bad Request HTML response when rendering an invalid write request. The issue is fixed in version 3.17.2. This vulnerability impacts deployments using Django REST framework versions prior to 3.17.2, allowing potential data disclosure. Defenders should assess exposure and prioritize upgrading to version 3.17 [truncated]
CVE-2026-73228 is a vulnerability in Django REST framework that allows oversized request bodies to consume additional memory and CPU, bypassing Django's DATA_UPLOAD_MAX_MEMORY_SIZE protection. The issue is fixed in version 3.17.2. This vulnerability can lead to potential denial-of-service attacks, emphasizing the need for defenders to assess exposure and prioritize upgrading to version 3.17.2 or later. Th [truncated]