The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade python-django | Jul 30, 2024 | May 2, 2013 |
| Freebsd | — | Upgrade py26-djangoUpgrade py27-django | Dec 10, 2025 | Feb 24, 2013 |
| Suse | — | Upgrade python-django | Dec 12, 2013 | May 2, 2013 |
| Ubuntu | — | Upgrade python-django | Nov 8, 2024 | May 2, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub