Pypi · Django Tastypie · CVE-2026-16207
**Name of the Vulnerable Software and Affected Versions**
django-tastypie versions prior to 0.15.2
**Description**
An information disclosure issue exists in the `ApiKeyAuthentication()` function within the `tastypie/authentication.py` file. A remote attacker can manipulate the system to use the GET request method with sensitive query strings, potentially exposing confidential data. This attack is characterized by high complexity and is considered difficult to exploit.
**Recommendations**
As a temporary workaround, restrict the use of the `ApiKeyAuthentication()` function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.