Improper control of interaction frequency in Django CRM - #VU153869
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service for other public web form visitors.
The vulnerability exists due to improper accounting of requests rejected by per-client rate limits in public web form endpoints when enforcing shared per-form limits. A remote attacker can repeatedly submit requests exceeding the per-client limit to exhaust the shared allowance and cause a denial of service for other public web form visitors.