VYPR

CWE-770

Allocation of Resources Without Limits or Throttling

BaseIncompleteLikelihood: High

Description

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528

CVEs mapped to this weakness (2,458)

page 11 of 123
  • CVE-2026-30070HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the HandleGetSharedData function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-30067HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-30063HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted snssais query.

  • CVE-2026-30060HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE registration.

  • CVE-2026-30059HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted Registration Request message.

  • CVE-2026-30057HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted request.

  • CVE-2026-30050HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request.

  • CVE-2026-47885HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28

  • CVE-2026-26445HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP connections open, which, combined with the broker s use of edge-triggered epoll (EPOLLET) and MSG_PEEK in recv(), causes sockets to enter a permanent half-read…

  • CVE-2026-59279HigAug 21, 2026
    risk 0.49cvss 7.5epss 0.00

    The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded…

  • CVE-2026-64773HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates…

  • CVE-2026-17170HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an allocation size.

  • CVE-2026-17163HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an array size field.

  • CVE-2026-73198HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded…

  • CVE-2026-73197HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into…

  • CVE-2026-47628HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service.

  • CVE-2026-73997HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.

  • CVE-2026-73062HigAug 16, 2026
    risk 0.49cvss 7.5epss 0.00

    Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multiplier in a template to force…

  • CVE-2026-73635HigAug 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the framework's internal…

  • CVE-2026-17199HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to unbounded resource allocation.