VYPR

CWE-400

Uncontrolled Resource Consumption

ClassDraftLikelihood: High

Description

The product does not properly control the allocation and maintenance of a limited resource.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-147 · CAPEC-227 · CAPEC-492

CVEs mapped to this weakness (3,835)

page 85 of 192
  • CVE-2025-2820MedMar 26, 2025
    risk 0.42cvss 6.5epss 0.01

    An authenticated attacker can compromise the availability of the device via the network

  • CVE-2025-30160HigMar 20, 2025
    risk 0.42cvss 7.5epss 0.01

    Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This…

  • CVE-2025-0191MedMar 20, 2025
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service (DoS) vulnerability exists in the file upload feature of gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large…

  • CVE-2024-9340HigMar 20, 2025
    risk 0.42cvss 7.5epss 0.01

    A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause excessive resource consumption by sending malformed multipart requests with arbitrary characters appended to the end of multipart boundaries. This flaw in the…

  • CVE-2024-8984HigMar 20, 2025
    risk 0.42cvss 7.5epss 0.01

    A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to…

  • CVE-2024-8966HigMar 20, 2025
    risk 0.42cvss 7.5epss 0.01

    A vulnerability in the file upload process of gradio-app/gradio version @gradio/[email protected] allows for a Denial of Service (DoS) attack. An attacker can append a large number of characters to the end of a multipart boundary, causing the system to continuously process each…

  • CVE-2024-12074MedMar 20, 2025
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webui version 1.10.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an…

  • CVE-2024-11033MedMar 20, 2025
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service (DoS) vulnerability exists in the file upload feature of binary-husky/gpt_academic version 3.83. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this vulnerability by sending…

  • CVE-2024-10188HigMar 20, 2025
    risk 0.42cvss 7.5epss 0.01

    A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of ast.literal_eval to parse user input. This function is not safe and is prone to DoS attacks, which can crash the litellm Python…

  • CVE-2025-29907HigMar 18, 2025
    risk 0.42cvss 7.5epss 0.01

    jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user control of the first argument of the addImage method results in CPU utilization and denial of service. If given the possibility to pass unsanitised image urls to the addImage method, a user can provide a…

  • CVE-2025-25293HigMar 12, 2025
    risk 0.42cvss 7.5epss 0.01

    ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case…

  • CVE-2025-27421HigMar 3, 2025
    risk 0.42cvss 7.5epss 0.00

    Abacus is a highly scalable and stateless counting API. A critical goroutine leak vulnerability has been identified in the Abacus server's Server-Sent Events (SSE) implementation. The issue occurs when clients disconnect from the /stream endpoint, as the server fails to properly…

  • CVE-2025-27097HigFeb 20, 2025
    risk 0.42cvss 7.5epss 0.00

    GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. When a user transforms on the root level or single…

  • CVE-2025-21352MedFeb 11, 2025
    risk 0.42cvss 6.5epss 0.01

    Internet Connection Sharing (ICS) Denial of Service Vulnerability

  • CVE-2024-54658MedFeb 10, 2025
    risk 0.42cvss 6.5epss 0.01

    The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to a denial-of-service.

  • CVE-2024-57085HigFeb 5, 2025
    risk 0.42cvss 7.5epss 0.00

    A prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

  • CVE-2024-57079HigFeb 5, 2025
    risk 0.42cvss 7.5epss 0.00

    A prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

  • CVE-2024-57075HigFeb 5, 2025
    risk 0.42cvss 7.5epss 0.01

    A prototype pollution in the lib.Logger function of eazy-logger v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

  • CVE-2024-53299MedJan 23, 2025
    risk 0.42cvss 6.5epss 0.02

    The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are recommended to upgrade to versions 9.19.0 or 10.3.0, which fixes this issue.

  • CVE-2024-57724MedJan 23, 2025
    risk 0.42cvss 6.5epss 0.00

    lunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell.