SB20261007218 - Multiple vulnerabilities in Django CRM
Published: October 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 vulnerabilities.
1) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to consume server and outbound-email resources and delay users' sign-in.
The vulnerability exists due to allocation of resources without per-client or site-wide throttling in MagicLinkRequestView when handling passwordless sign-in requests. A remote attacker can submit requests using different recipient addresses or exhaust a specific recipient's hourly allowance to consume server and outbound-email resources and delay users' sign-in.
Each request creates a sign-in token and queues an email, and recipients need not be registered users. Targeted sign-in delays can last up to an hour, but a generated link still reaches the recipient's inbox. Exploitation does not provide authentication bypass, data disclosure, or access to another user's account.
2) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to consume server and outbound-email resources and delay users' sign-in.
The vulnerability exists due to allocation of resources without per-client or overall throttling in PortalLoginRequestView when handling portal sign-in requests. A remote attacker can submit requests using different recipient addresses or exhaust a specific recipient's hourly allowance to consume server and outbound-email resources and delay users' sign-in.
Email is sent only to existing contacts of the specified organization; requests for other addresses incur a database lookup instead. Targeted sign-in delays can last up to an hour, but a generated link still reaches the recipient's inbox. Exploitation does not provide authentication bypass, data disclosure, or access to another user's account.
3) Improper control of interaction frequency (CVE-ID: N/A)
CWE-ID: CWE-799 - Improper Control of Interaction Frequency
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service for other public web form visitors.
The vulnerability exists due to improper accounting of requests rejected by per-client rate limits in public web form endpoints when enforcing shared per-form limits. A remote attacker can repeatedly submit requests exceeding the per-client limit to exhaust the shared allowance and cause a denial of service for other public web form visitors.
4) Improper control of interaction frequency (CVE-ID: N/A)
CWE-ID: CWE-799 - Improper Control of Interaction Frequency
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service for other help center visitors.
The vulnerability exists due to improper accounting of requests rejected by per-client rate limits in help center endpoints when enforcing shared per-help-center limits. A remote attacker can repeatedly submit requests exceeding the per-client limit to exhaust the shared allowance and cause a denial of service for other help center visitors.
5) Improper control of interaction frequency (CVE-ID: N/A)
CWE-ID: CWE-799 - Improper Control of Interaction Frequency
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service for other calendar feed visitors.
The vulnerability exists due to improper accounting of requests rejected by per-client rate limits in calendar feed endpoints when enforcing shared per-feed limits. A remote attacker can repeatedly submit requests exceeding the per-client limit to exhaust the shared allowance and cause a denial of service for other calendar feed visitors.
Remediation
Install update from vendor's website.