CVE-2026-16208
MEDIUMdjango-tastypie throttle.py CacheDBThrottle race condition
Title source: cnaDescription
A flaw has been found in django-tastypie up to 0.15.1. The affected element is the function CacheThrottle/CacheDBThrottle of the file tastypie/throttle.py. This manipulation causes race condition. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitability is described as difficult. The project was informed of the problem early through an issue report but has not responded yet.
References (6)
Core 6
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-380024 | django-tastypie throttle.py CacheDBThrottle race condition
https://vuldb.com/vuln/380024
Signature, Permissions Required signature
permissions-required
VDB-380024 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/380024/cti
Third Party Advisory third-party-advisory
CVE-2026-16208 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-16208
Third Party Advisory third-party-advisory
Submit #857925 | django-tastypie 0.15.1 at commit 03c4746f0a0f88628be5264bc8d4a19a0529b2f4 CWE-362 Concurrent Execution using Shared Resource with Improper
https://vuldb.com/submit/857925
Issue Tracking issue-tracking
https://github.com/django-tastypie/django-tastypie/issues/1700
Product product
https://github.com/django-tastypie/django-tastypie/
Scores
CVSS v3
5.0
EPSS
0.0017
EPSS Percentile
6.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-362
Status
published
Products (2)
None/django-tastypie
0.15.0
None/django-tastypie
0.15.1
Published
Jul 19, 2026
Tracked Since
Jul 19, 2026