VYPR

CWE-770

Allocation of Resources Without Limits or Throttling

BaseIncompleteLikelihood: High

Description

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528

CVEs mapped to this weakness (2,457)

page 101 of 123
  • CVE-2026-26477MedApr 3, 2026
    risk 0.28cvss 4.3epss 0.00

    An issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the media_upload_xhr() function in the media.php file

  • CVE-2026-5316MedApr 2, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file stb_vorbis.c. The manipulation leads to allocation of resources. The attack is possible to be carried out remotely. The exploit is publicly available and might…

  • CVE-2025-68659MedJan 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have an application level denial of service vulnerabilityin the username change functionality at try.discourse.org. The vulnerability allows attackers to cause noticeable…

  • CVE-2026-23963MedJan 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the server does not enforce a maximum length for the names of lists or filters, or for filter keywords, allowing any user to set an arbitrarily long string as…

  • CVE-2026-22917MedJan 15, 2026
    risk 0.28cvss 4.3epss 0.01

    Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service.

  • CVE-2025-64422MedJan 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertises a rate limit of 5 requests but can be trivially bypassed by rotating the X-Forwarded-For header.…

  • CVE-2025-41693MedDec 9, 2025
    risk 0.28cvss 4.3epss 0.01

    A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays open and uses resources which leads to a reduced performance of the management functions. Switching functionality is not affected.

  • CVE-2025-54320MedNov 18, 2025
    risk 0.28cvss 4.3epss 0.00

    In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating invite requests.

  • CVE-2025-2934MedOct 9, 2025
    risk 0.28cvss 4.3epss 0.01

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring malicious webhook endpoints…

  • CVE-2025-11042MedSep 26, 2025
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while using…

  • CVE-2025-7070MedJul 4, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component MFA Pairing Request Handler. The manipulation leads to allocation of resources. The attack needs to be…

  • CVE-2025-52917MedJun 21, 2025
    risk 0.28cvss 4.3epss 0.00

    The Yealink RPS API before 2025-05-26 lacks rate limiting, potentially enabling information disclosure via excessive requests.

  • CVE-2025-4432MedMay 9, 2025
    risk 0.28cvss 5.3epss 0.01

    A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32…

  • CVE-2024-51461MedApr 11, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM QRadar WinCollect Agent 10.0 through 10.1.13 could allow a remote attacker to cause a denial of service by interrupting an HTTP request that could consume memory resources.

  • CVE-2024-10307MedMar 28, 2025
    risk 0.28cvss 4.3epss 0.00

    An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A maliciously crafted file can cause uncontrolled CPU consumption when viewing the associated merge request.

  • CVE-2025-27795MedMar 7, 2025
    risk 0.28cvss 4.3epss 0.00

    ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.

  • CVE-2023-51310MedFeb 20, 2025
    risk 0.28cvss 4.3epss 0.01

    A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail…

  • CVE-2023-51309MedFeb 20, 2025
    risk 0.28cvss 4.3epss 0.01

    A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

  • CVE-2024-38316MedFeb 5, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

  • CVE-2024-56332MedJan 3, 2025
    risk 0.28cvss 5.3epss 0.01

    Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, Next.js is vulnerable to a Denial of Service (DoS) attack that allows attackers to construct requests that leaves requests to…