VYPR

CWE-405

Asymmetric Resource Consumption (Amplification)

ClassIncomplete

Description

The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."

This can lead to poor performance due to "amplification" of resource consumption, typically in a non-linear fashion. This situation is worsened if the product allows malicious users or attackers to consume more resources than their access level permits.

Hierarchy (View 1000)

CVEs mapped to this weakness (59)

page 3 of 3
  • CVE-2026-23934MedAug 18, 2026
    risk 0.33cvss —epss 0.00

    An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.

  • CVE-2026-8594MedMay 30, 2026
    risk 0.33cvss 6.2epss 0.00

    Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters. Text::LineFold splits the input string by specific line break characters (such as VT, FF and others) into segments, but applies the break function to the…

  • CVE-2024-0450MedMar 19, 2024
    risk 0.33cvss 6.2epss 0.00

    An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The…

  • CVE-2025-31987MedAug 14, 2025
    risk 0.31cvss 4.8epss 0.00

    HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion.

  • CVE-2022-23500MedDec 14, 2022
    risk 0.31cvss 5.9epss 0.01

    TYPO3 is an open source PHP based web content management system. In versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1, requesting invalid or non-existing resources via HTTP triggers the page error handler, which again could retrieve content to be shown as an error message…

  • CVE-2024-34702MedJul 8, 2024
    risk 0.28cvss 5.3epss 0.01

    Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to 3.5.0 and 2.19.5, checking name constraints in X.509 certificates is quadratic in the number of names…

  • CVE-2026-35665MedApr 10, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook handler accepts request bodies with permissive limits of 1MB and 30-second timeout before signature verification. An unauthenticated attacker can exhaust server connection resources…

  • CVE-2026-35626MedApr 9, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling that buffers request bodies before provider signature checks. Attackers can send large or malicious webhook requests to exhaust server resources without…

  • CVE-2025-46598MedMar 20, 2026
    risk 0.27cvss 5.3epss 0.00

    Bitcoin Core through 29.0 allows a denial of service via a crafted transaction.

  • CVE-2025-68480MedDec 22, 2025
    risk 0.27cvss 5.3epss 0.00

    Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request…

  • CVE-2026-84310MedSep 1, 2026
    risk 0.24cvss —epss 0.00

    pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines with large numbers of entries or deeply…

  • CVE-2026-82309MedSep 4, 2026
    risk 0.21cvss 4.3epss 0.00

    Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries. _check_dns issues one PTR query for the client address, keeps the returned names matching…

  • CVE-2024-28214LowMar 7, 2024
    risk 0.18cvss 2.7epss 0.01

    nGrinder before 3.5.9 allows to set delay without limitation, which could be the cause of Denial of Service by remote attacker.

  • CVE-2026-68531LowSep 15, 2026
    risk 0.07cvss —epss 0.00

    Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file folders, and page list, allowing an authenticated user with editor-level or higher privileges to submit a crafted search containing many…

  • CVE-2019-11479HigJun 19, 2019
    risk 0.07cvss 7.5epss 0.92

    Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been…

  • CVE-2025-32394MedJun 26, 2026
    risk 0.00cvss —epss 0.00

    AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in AITextSummarizerBlock. Malicious users can amplify their input. For example, if a malicious user inputs 10K…

  • CVE-2026-54224HigJun 18, 2026
    risk 0.00cvss —epss 0.00

    UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile on instances with many registered users, an authenticated attacker can easily exhaust database resources and completely deny access to the application for other…

  • CVE-2025-24356HigJan 27, 2025
    risk 0.00cvss 7.5epss 0.01

    fastd is a VPN daemon which tunnels IP packets and Ethernet frames over UDP. When receiving a data packet from an unknown IP address/port combination, fastd will assume that one of its connected peers has moved to a new address and initiate a reconnect by sending a handshake…

  • CVE-2024-55628HigJan 6, 2025
    risk 0.00cvss 7.5epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.8, DNS resource name compression can lead to small DNS messages containing very large hostnames which can be costly to decode, and lead to…