VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,811)

page 168 of 191
  • CVE-2025-61620medOct 7, 2025
    risk 0.19cvss epss 0.00

    ### Summary A resource-exhaustion (denial-of-service) vulnerability exists in multiple endpoints of the OpenAI-Compatible Server due to the ability to specify Jinja templates via the `chat_template` and `chat_template_kwargs` parameters. If an attacker can supply these…

  • CVE-2025-27576LowAug 12, 2025
    risk 0.19cvss 2.9epss 0.00

    Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an unauthenticated user to potentially enable denial of service via local access.

  • CVE-2022-24902LowMay 6, 2022
    risk 0.19cvss 2.9epss 0.01

    TkVideoplayer is a simple library to play video files in tkinter. Uncontrolled memory consumption in versions of TKVideoplayer prior to 2.0.0 can theoretically lead to performance degradation. There are no known workarounds. This issue has been patched and users are advised to…

  • CVE-2026-6416LowApr 22, 2026
    risk 0.18cvss 2.7epss 0.00

    Tanium addressed an uncontrolled resource consumption vulnerability in Interact.

  • CVE-2025-50104LowJul 15, 2025
    risk 0.18cvss 2.7epss 0.00

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols…

  • CVE-2025-50098LowJul 15, 2025
    risk 0.18cvss 2.7epss 0.00

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple…

  • CVE-2025-4533LowMay 11, 2025
    risk 0.18cvss 2.7epss 0.01

    A vulnerability classified as problematic was found in JeecgBoot up to 3.8.0. This vulnerability affects the function unzipFile of the file /jeecg-boot/airag/knowledge/doc/import/zip of the component Document Library Upload. The manipulation of the argument File leads to…

  • CVE-2025-3985LowApr 27, 2025
    risk 0.18cvss 2.7epss 0.01

    A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function ResponseEntity of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\ManageRegisteredServicesMultiActionControl…

  • CVE-2025-30681LowApr 15, 2025
    risk 0.18cvss 2.7epss 0.01

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple…

  • CVE-2022-4003LowJul 31, 2024
    risk 0.18cvss 2.7epss 0.00

    A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request.

  • CVE-2023-44321LowNov 14, 2023
    risk 0.18cvss 2.7epss 0.01

    Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web interface allowing an authenticated attacker to cause a denial of service condition. The device needs to be restarted for the web interface to become available…

  • CVE-2022-43893LowOct 17, 2023
    risk 0.18cvss 2.7epss 0.00

    IBM Security Verify Privilege On-Premises 11.5 could allow a privileged user to cause by using a malicious payload. IBM X-Force ID: 240634.

  • CVE-2023-28440LowApr 18, 2023
    risk 0.18cvss 2.7epss 0.01

    Discourse is an open source platform for community discussion. In affected versions a maliciously crafted request from a Discourse administrator can lead to a long-running request and eventual timeout. This has the greatest potential impact in shared hosting environments where…

  • CVE-2026-44242LowMay 12, 2026
    risk 0.17cvss 3.7epss 0.00

    Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Prior to 4.10.22, the bundleCache is keyed by (Locale, baseName) where the locale originates from the HTTP Accept-Language header. In applications that…

  • CVE-2026-41913LowApr 28, 2026
    risk 0.17cvss 3.7epss 0.00

    OpenClaw before 2026.4.4 contains a race condition vulnerability in shared-secret authentication that allows concurrent asynchronous requests to bypass the per-key rate-limit budget. Attackers can exploit this by sending multiple simultaneous authentication attempts to…

  • CVE-2026-34166LowApr 8, 2026
    risk 0.17cvss 3.7epss 0.01

    LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter in LiquidJS incorrectly accounts for memory usage when the memoryLimit option is enabled. It charges str.length + pattern.length + replacement.length bytes to…

  • CVE-2025-4727LowMay 15, 2025
    risk 0.17cvss 3.7epss 0.01

    A vulnerability was found in Meteor up to 3.2.1 and classified as problematic. This issue affects the function Object.assign of the file packages/ddp-server/livedata_server.js. The manipulation of the argument forwardedFor leads to inefficient regular expression complexity. The…

  • CVE-2023-49559LowJun 12, 2024
    risk 0.17cvss 3.7epss 0.01

    An issue in vektah gqlparser open-source-library v.2.5.10 allows a remote attacker to cause a denial of service via a crafted script to the parserDirectives function.

  • CVE-2024-34079LowMay 14, 2024
    risk 0.17cvss 3.7epss 0.01

    octo-sts is a GitHub App that acts like a Security Token Service (STS) for the Github API. This vulnerability can spike the resource utilization of the STS service, and combined with a significant traffic volume could potentially lead to a denial of service. This vulnerability…

  • CVE-2024-1410LowMar 12, 2024
    risk 0.17cvss 3.7epss 0.01

    Cloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1…