VYPR

CWE-770

Allocation of Resources Without Limits or Throttling

BaseIncompleteLikelihood: High

Description

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528

CVEs mapped to this weakness (2,458)

page 10 of 123
  • CVE-2026-87742HigSep 17, 2026
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application can process them. Due to unbounded message buffering and a lack of read…

  • CVE-2026-1168HigSep 16, 2026
    risk 0.49cvss 7.5epss 0.01

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation…

  • CVE-2025-14871HigSep 16, 2026
    risk 0.49cvss 7.5epss 0.01

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation…

  • CVE-2026-13260HigSep 14, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

  • CVE-2026-91080HigSep 14, 2026
    risk 0.49cvss 7.5epss 0.01

    webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signatures to trigger out-of-memory…

  • CVE-2026-90668HigSep 13, 2026
    risk 0.49cvss 7.5epss 0.00

    The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with an unlimited number of headers, if a…

  • CVE-2026-57099HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.01

    Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

  • CVE-2026-82075HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    An uncontrolled resource consumption weakness exists in the request-handling path of the MongoDB sharded-cluster router process. A client that has network access to a router port and has not authenticated can supply connection-monitoring parameters that cause the server to…

  • CVE-2026-62649HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or manage system resources when processing a high volume of concurrent HTTP requests. This could allow an unauthenticated remote attacker to cause the entire…

  • CVE-2026-48888HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.

  • CVE-2026-84778HigSep 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions.

  • CVE-2026-84776HigSep 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.

  • CVE-2026-71257HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.01

    Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request body has already been consumed by another component, Commons FileUpload returns no items and Wicket falls back to…

  • CVE-2026-19873HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.01

    HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. When a Repeatable element has counter_name set, its process method reads the repeat count from the named query string parameter,…

  • CVE-2026-81624HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being…

  • CVE-2026-81285HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.

  • CVE-2026-59289HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memory or place…

  • CVE-2026-5680HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using…

  • CVE-2026-30073HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2026-30071HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.