Allocation of Resources Without Limits or Throttling in Django CRM - #VU153868

 

Allocation of Resources Without Limits or Throttling in Django CRM - #VU153868

Published: October 7, 2026


Vulnerability identifier: #VU153868
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to consume server and outbound-email resources and delay users' sign-in.

The vulnerability exists due to allocation of resources without per-client or overall throttling in PortalLoginRequestView when handling portal sign-in requests. A remote attacker can submit requests using different recipient addresses or exhaust a specific recipient's hourly allowance to consume server and outbound-email resources and delay users' sign-in.

Email is sent only to existing contacts of the specified organization; requests for other addresses incur a database lookup instead. Targeted sign-in delays can last up to an hour, but a generated link still reaches the recipient's inbox. Exploitation does not provide authentication bypass, data disclosure, or access to another user's account.


Affected software

Django CRM

Remediation

Install security update from vendor's website.

Django CRM - update to 1.14.5

External References

Related Security Bulletins