{"id":"PYSEC-2013-17","details":"The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.","aliases":["CVE-2013-0306","GHSA-g8xg-jgj6-49r3"],"modified":"2026-06-10T17:00:47.476398892Z","published":"2013-05-02T14:55:00Z","references":[{"type":"ARTICLE","url":"https://www.djangoproject.com/weblog/2013/feb/19/security/"},{"type":"ADVISORY","url":"http://www.debian.org/security/2013/dsa-2634"},{"type":"WEB","url":"http://ubuntu.com/usn/usn-1757-1"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2013-0670.html"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g8xg-jgj6-49r3"}],"affected":[{"package":{"name":"django","ecosystem":"PyPI","purl":"pkg:pypi/django"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.3"},{"fixed":"1.3.6"},{"introduced":"1.4"},{"fixed":"1.4.4"}]}],"versions":["1.3","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5","1.4","1.4.1","1.4.2","1.4.3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/django/PYSEC-2013-17.yaml"}}],"schema_version":"1.7.5"}