Improper control of interaction frequency in Django CRM - #VU153871
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service for other calendar feed visitors.
The vulnerability exists due to improper accounting of requests rejected by per-client rate limits in calendar feed endpoints when enforcing shared per-feed limits. A remote attacker can repeatedly submit requests exceeding the per-client limit to exhaust the shared allowance and cause a denial of service for other calendar feed visitors.