VYPR

CWE-770

Allocation of Resources Without Limits or Throttling

BaseIncompleteLikelihood: High

Description

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528

CVEs mapped to this weakness (2,224)

page 103 of 112
  • CVE-2026-16971MedJul 30, 2026
    risk 0.00cvss 5.9epss 0.00

    The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.

  • CVE-2026-15975HigJul 29, 2026
    risk 0.00cvss 7.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling…

  • CVE-2026-54609HigJul 28, 2026
    risk 0.00cvss 8.6epss 0.00

    QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and…

  • CVE-2026-61609HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.00

    Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() applied a single global bucket to the login and two-factor checkpoint endpoints instead of keying by…

  • CVE-2026-47483HigJul 28, 2026
    risk 0.00cvss 8.2epss 0.00

    NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to…

  • CVE-2026-8287MedJul 23, 2026
    risk 0.00cvss 4.3epss 0.00

    Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation. This issue affects Online Pre-Accounting Software: through 17072026.

  • CVE-2026-13076MedJul 22, 2026
    risk 0.00cvss 6.5epss 0.00

    An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation within MongoDB's aggregation framework. The behavior stems from disproportionate memory consumption during…

  • CVE-2026-13075MedJul 22, 2026
    risk 0.00cvss 6.5epss 0.00

    An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusion aggregation stages. The issue originates in the server's error-handling path and requires the ability to run aggregation queries.

  • CVE-2026-13074MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.00

    An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination results in a response loop that bypasses normal…

  • CVE-2026-65650MedJul 22, 2026
    risk 0.00cvss 4.3epss 0.00

    Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.

  • CVE-2026-11622HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.01

    A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of…

  • CVE-2026-15957HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. Uncontrolled recursion in the JSON, CBOR, and XML deserializer functions…

  • CVE-2026-44907HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack…

  • CVE-2026-53596MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does not enforce rate limiting on the file upload endpoint. Any user can flood the server with upload requests, leading to database…

  • CVE-2026-48824MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-45710, "Mailpit: Set a default 50MB p/m limit to prevent DoS via unlimited SMTP DATA and /api/v1/send body sizes") wrapped only `POST /api/v1/send` with…

  • CVE-2026-63750MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attackers to buffer unbounded frames in the per-connection read buffer. Attackers can stream WebSocket frames larger than the configured…

  • CVE-2026-50272HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/baggage.js and packages/dd-trace/src/opentracing/propagation/text_map.js parsed incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or…

  • CVE-2026-50271HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES limits on the extract path. A…

  • CVE-2026-48504MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound baggage header, so a large attacker-controlled header could cause…

  • CVE-2026-50273HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on…