Lucene search

K
osvGoogleOSV:PYSEC-2013-17
HistoryMay 02, 2013 - 2:55 p.m.

PYSEC-2013-17

2013-05-0214:55:00
Google
osv.dev
17

EPSS

0.009

Percentile

82.9%

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.