Executive brief
A security issue in the django-tastypie library allows sensitive API keys to be passed through web addresses (URLs) instead of secure headers. This practice can lead to the accidental exposure of login credentials in server logs, browser history, and shared links, potentially allowing unauthorized individuals to access user accounts. The library is commonly used to build web interfaces for Django-based applications.
Technical details
The ApiKeyAuthentication class in tastypie/authentication.py (specifically versions up to 0.15.1) is vulnerable to CWE-598. The implementation accepts 'username' and 'api_key' credentials from GET or POST parameters when a valid Authorization header is missing. This results in sensitive authentication tokens being recorded in plaintext within web server access logs, proxy logs, browser history, and Referer headers. An attacker with access to these logs or shared URLs can hijack the victim's session. While the attack is remote, it is classified as high complexity because it requires the attacker to gain access to secondary data sources (like logs) or for a user to inadvertently share a URL containing their credentials.
Affected products
- django-tastypie django-tastypie <= 0.15.1
Timeline
- 2026-06-13: disclosed: Issue reported to the project maintainers via GitHub issue #1700
- 2026-07-19: advisory: CVE published by VulDB/NVD