SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-16207

LOW · CVSS 3.7 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-17

CyberRota Analysis

AI-Generated

A vulnerability exists in the ApiKeyAuthentication function of django-tastypie versions up to 0.15.1, allowing remote attackers to manipulate GET request methods to expose sensitive query strings. Although the exploit requires high complexity and is considered difficult to execute, organizations using this library should prioritize patching to mitigate potential data exposure risks. Users of django-tastypie should remain vigilant and monitor for updates, as the project maintainers have yet to address the issue.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16207
Severity
LOW
CVSS
3.7
EPSS
0.40%

Original NVD Description

A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthentication of the file tastypie/authentication.py. The manipulation results in use of get request method with sensitive query strings. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult. The project was informed of the problem early through an issue report but has not responded yet.