VYPR

CWE-408

Incorrect Behavior Order: Early Amplification

BaseDraft

Description

The product allows an entity to perform a legitimate but expensive operation before authentication or authorization has taken place.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (7)

  • CVE-2020-1657HigOct 16, 2020
    risk 0.49cvss 7.5epss 0.01

    On SRX Series devices, a vulnerability in the key-management-daemon (kmd) daemon of Juniper Networks Junos OS allows an attacker to spoof packets targeted to IPSec peers before a security association (SA) is established thereby causing a failure to set up the IPSec channel.…

  • CVE-2026-41405HigApr 28, 2026
    risk 0.42cvss 7.5epss 0.00

    OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthenticated attackers to trigger resource exhaustion. Remote attackers can send malicious Teams webhook payloads to exhaust server resources by bypassing…

  • CVE-2022-2576HigJul 29, 2022
    risk 0.42cvss 7.5epss 0.01

    In Eclipse Californium version 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS full handshake on a parameter mismatch without using a HelloVerifyRequest. Especially, if used with certificate based cipher suites, that results in message…

  • CVE-2026-3592MedMay 20, 2026
    risk 0.34cvss 5.3epss 0.00

    BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through…

  • CVE-2026-41374MedApr 28, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowing unauthenticated attackers to consume resources. Remote attackers can trigger audio preflight processing without member allowlist validation to cause resource…

  • CVE-2026-41331MedApr 21, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenClaw before 2026.3.31 contains a resource consumption vulnerability in Telegram audio preflight transcription that allows unauthorized group senders to trigger transcription processing. Attackers can exploit insufficient allowlist enforcement to cause resource or billing…

  • CVE-2026-11605HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.01

    The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes…