VYPR

CWE-770

Allocation of Resources Without Limits or Throttling

BaseIncompleteLikelihood: High

Description

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528

CVEs mapped to this weakness (2,457)

page 110 of 123
  • CVE-2023-3566LowJul 10, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in wallabag 2.5.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /config of the component Profile Config. The manipulation of the argument Name leads to allocation of resources. The exploit…

  • CVE-2022-45471LowNov 18, 2022
    risk 0.23cvss 3.5epss 0.01

    In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address

  • CVE-2022-1333LowApr 13, 2022
    risk 0.23cvss 3.5epss 0.01

    Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorized users to create a specifically drafted Playbook which could trigger a large amount of webhook requests leading to Denial of…

  • CVE-2026-26998MedMar 5, 2026
    risk 0.22cvss 4.4epss 0.00

    Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerability in Traefik managing the ForwardAuth middleware responses. When Traefik is configured to use the ForwardAuth middleware, the response body from the…

  • CVE-2023-37900LowJul 27, 2023
    risk 0.22cvss 3.4epss 0.01

    Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, a high-privileged user could create a Package referencing an arbitrarily large image containing that Crossplane would then parse,…

  • CVE-2017-2587LowJul 27, 2018
    risk 0.22cvss 3.3epss 0.01

    A memory allocation vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause the application to crash.

  • CVE-2026-54247MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly to io.ReadAll(r.Body) without a size…

  • CVE-2026-11993MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with permission to upload files to spawn more goroutines than…

  • CVE-2023-54394MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    PocketMine-MP before 4.18.0-ALPHA2 fails to rate-limit mismatch type InventoryTransactionPacket requests, allowing attackers to trigger excessive inventory synchronization. Attackers can send numerous mismatch transactions to force the server to transmit large amounts of…

  • CVE-2026-82309MedSep 4, 2026
    risk 0.21cvss 4.3epss 0.00

    Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries. _check_dns issues one PTR query for the client address, keeps the returned names matching…

  • CVE-2026-75841MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticated users to exhaust server heap memory. Attackers can submit oversized range() expressions with large bounds to trigger OutOfMemoryError and cause temporary…

  • CVE-2026-71486MedAug 17, 2026
    risk 0.21cvss 4.3epss 0.00

    vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied GenerateResponse objects whose generate_responses, choices, token_ids, prompt_logprobs,…

  • CVE-2026-59763MedAug 13, 2026
    risk 0.21cvss 4.3epss 0.00

    Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

  • CVE-2026-18096LowAug 12, 2026
    risk 0.21cvss 3.3epss 0.00

    IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak.

  • CVE-2026-10600MedJul 27, 2026
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all…

  • CVE-2026-62641MedJul 14, 2026
    risk 0.21cvss 4.3epss 0.00

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.

  • CVE-2026-49337MedJun 19, 2026
    risk 0.21cvss 4.3epss 0.00

    libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image…

  • CVE-2026-53781MedJun 11, 2026
    risk 0.21cvss 4.3epss 0.00

    Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforced size limit through missing or misreported Content-Length headers, chunked transfer encoding, or failed…

  • CVE-2026-49140MedJun 1, 2026
    risk 0.21cvss 4.3epss 0.00

    Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler that allows authenticated room members to exhaust process memory and bandwidth by sending media events with missing or invalid size metadata. Attackers can send…

  • CVE-2026-2325MedMay 18, 2026
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body on the start meeting API endpoint, which allows an authenticated attacker to cause resource exhaustion or denial of service via a crafted oversized HTTP POST…