Allocation of Resources Without Limits or Throttling in Django CRM - #VU153868
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to consume server and outbound-email resources and delay users' sign-in.
The vulnerability exists due to allocation of resources without per-client or overall throttling in PortalLoginRequestView when handling portal sign-in requests. A remote attacker can submit requests using different recipient addresses or exhaust a specific recipient's hourly allowance to consume server and outbound-email resources and delay users' sign-in.
Email is sent only to existing contacts of the specified organization; requests for other addresses incur a database lookup instead. Targeted sign-in delays can last up to an hour, but a generated link still reaches the recipient's inbox. Exploitation does not provide authentication bypass, data disclosure, or access to another user's account.