VYPR

CWE-770

Allocation of Resources Without Limits or Throttling

BaseIncompleteLikelihood: High

Description

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528

CVEs mapped to this weakness (2,485)

page 113 of 125
  • CVE-2019-14834LowJan 7, 2020
    risk 0.24cvss 3.7epss 0.03

    A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.

  • CVE-2025-52657LowSep 7, 2026
    risk 0.23cvss 3.5epss 0.00

    HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the number of characters which can impact system performance or availability.

  • CVE-2025-1823LowFeb 4, 2026
    risk 0.23cvss 3.5epss 0.00

    IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resources.

  • CVE-2025-10867LowSep 26, 2025
    risk 0.23cvss 3.5epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to create a denial-of-service condition by exploiting an unprotected GraphQL API through repeated…

  • CVE-2023-3566LowJul 10, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in wallabag 2.5.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /config of the component Profile Config. The manipulation of the argument Name leads to allocation of resources. The exploit…

  • CVE-2022-45471LowNov 18, 2022
    risk 0.23cvss 3.5epss 0.01

    In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address

  • CVE-2022-1333LowApr 13, 2022
    risk 0.23cvss 3.5epss 0.01

    Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorized users to create a specifically drafted Playbook which could trigger a large amount of webhook requests leading to Denial of…

  • CVE-2026-26998MedMar 5, 2026
    risk 0.22cvss 4.4epss 0.01

    Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerability in Traefik managing the ForwardAuth middleware responses. When Traefik is configured to use the ForwardAuth middleware, the response body from the…

  • CVE-2023-37900LowJul 27, 2023
    risk 0.22cvss 3.4epss 0.01

    Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, a high-privileged user could create a Package referencing an arbitrarily large image containing that Crossplane would then parse,…

  • CVE-2017-2587LowJul 27, 2018
    risk 0.22cvss 3.3epss 0.01

    A memory allocation vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause the application to crash.

  • CVE-2026-54247MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly to io.ReadAll(r.Body) without a size…

  • CVE-2026-11993MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with permission to upload files to spawn more goroutines than…

  • CVE-2023-54394MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    PocketMine-MP before 4.18.0-ALPHA2 fails to rate-limit mismatch type InventoryTransactionPacket requests, allowing attackers to trigger excessive inventory synchronization. Attackers can send numerous mismatch transactions to force the server to transmit large amounts of…

  • CVE-2026-82309MedSep 4, 2026
    risk 0.21cvss 4.3epss 0.00

    Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries. _check_dns issues one PTR query for the client address, keeps the returned names matching…

  • CVE-2026-75841MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticated users to exhaust server heap memory. Attackers can submit oversized range() expressions with large bounds to trigger OutOfMemoryError and cause temporary…

  • CVE-2026-71486MedAug 17, 2026
    risk 0.21cvss 4.3epss 0.00

    vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied GenerateResponse objects whose generate_responses, choices, token_ids, prompt_logprobs,…

  • CVE-2026-59763MedAug 13, 2026
    risk 0.21cvss 4.3epss 0.00

    Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

  • CVE-2026-18096LowAug 12, 2026
    risk 0.21cvss 3.3epss 0.00

    IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak.

  • CVE-2026-10600MedJul 27, 2026
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all…

  • CVE-2026-62641MedJul 14, 2026
    risk 0.21cvss 4.3epss 0.00

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.