Allocation of Resources Without Limits or Throttling in Django CRM - #VU153867

 

Allocation of Resources Without Limits or Throttling in Django CRM - #VU153867

Published: October 7, 2026


Vulnerability identifier: #VU153867
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to consume server and outbound-email resources and delay users' sign-in.

The vulnerability exists due to allocation of resources without per-client or site-wide throttling in MagicLinkRequestView when handling passwordless sign-in requests. A remote attacker can submit requests using different recipient addresses or exhaust a specific recipient's hourly allowance to consume server and outbound-email resources and delay users' sign-in.

Each request creates a sign-in token and queues an email, and recipients need not be registered users. Targeted sign-in delays can last up to an hour, but a generated link still reaches the recipient's inbox. Exploitation does not provide authentication bypass, data disclosure, or access to another user's account.


Affected software

Django CRM

Remediation

Install security update from vendor's website.

Django CRM - update to 1.14.5

External References

Related Security Bulletins