CVE-2026-16208

MEDIUM

django-tastypie throttle.py CacheDBThrottle race condition

Title source: cna
STIX 2.1

Description

A flaw has been found in django-tastypie up to 0.15.1. The affected element is the function CacheThrottle/CacheDBThrottle of the file tastypie/throttle.py. This manipulation causes race condition. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitability is described as difficult. The project was informed of the problem early through an issue report but has not responded yet.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-380024 | django-tastypie throttle.py CacheDBThrottle race condition
https://vuldb.com/vuln/380024
Signature, Permissions Required signature permissions-required
VDB-380024 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/380024/cti
Third Party Advisory third-party-advisory
CVE-2026-16208 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-16208
Third Party Advisory third-party-advisory
Submit #857925 | django-tastypie 0.15.1 at commit 03c4746f0a0f88628be5264bc8d4a19a0529b2f4 CWE-362 Concurrent Execution using Shared Resource with Improper
https://vuldb.com/submit/857925

Scores

CVSS v3 5.0
EPSS 0.0017
EPSS Percentile 6.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-362
Status published
Products (2)
None/django-tastypie 0.15.0
None/django-tastypie 0.15.1
Published Jul 19, 2026
Tracked Since Jul 19, 2026