Allocation of Resources Without Limits or Throttling in Django CRM - #VU153867
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to consume server and outbound-email resources and delay users' sign-in.
The vulnerability exists due to allocation of resources without per-client or site-wide throttling in MagicLinkRequestView when handling passwordless sign-in requests. A remote attacker can submit requests using different recipient addresses or exhaust a specific recipient's hourly allowance to consume server and outbound-email resources and delay users' sign-in.
Each request creates a sign-in token and queues an email, and recipients need not be registered users. Targeted sign-in delays can last up to an hour, but a generated link still reaches the recipient's inbox. Exploitation does not provide authentication bypass, data disclosure, or access to another user's account.