VYPR

CWE-770

Allocation of Resources Without Limits or Throttling

BaseIncompleteLikelihood: High

Description

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528

CVEs mapped to this weakness (2,458)

page 13 of 123
  • CVE-2026-12733HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.

  • CVE-2026-16308HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.

  • CVE-2026-59899HigJul 29, 2026
    risk 0.49cvss 7.5epss 0.00

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque` named…

  • CVE-2026-16756HigJul 23, 2026
    risk 0.49cvss 7.5epss 0.01

    Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are…

  • CVE-2026-59762HigJul 15, 2026
    risk 0.49cvss 7.5epss 0.01

    When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.   Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability…

  • CVE-2026-50651HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50648HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50525HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

  • CVE-2026-47302HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

  • CVE-2026-56170HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

  • CVE-2026-9140HigJul 14, 2026
    risk 0.49cvss —epss 0.00

    A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover.

  • CVE-2026-31984HigJul 9, 2026
    risk 0.49cvss 7.5epss 0.01

    A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size limit on input recorded into audit entries. An unauthenticated attacker can submit requests containing excessively large input that…

  • CVE-2025-61028HigJun 23, 2026
    risk 0.49cvss 7.5epss 0.01

    An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2026-48515HigJun 22, 2026
    risk 0.49cvss 7.5epss 0.00

    MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's multi-dimensional array formatters read dimension lengths directly from the payload and allocate T[,], T[,,], or T[,,,] before validating that the dimension product matches…

  • CVE-2026-48514HigJun 22, 2026
    risk 0.49cvss 7.5epss 0.00

    MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, UnsafeBlitFormatterBase.Deserialize reads an attacker-controlled byteLength from an extension payload and allocates an array based on that value before validating it against the extension…

  • CVE-2026-48510HigJun 22, 2026
    risk 0.49cvss 7.5epss 0.00

    MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or Lz4BlockArray payloads, it reads declared uncompressed lengths from the wire and allocates output buffers based on those lengths before validating…

  • CVE-2026-47774HigJun 17, 2026
    risk 0.49cvss 7.5epss 0.01

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remote client to trigger excessive memory…

  • CVE-2026-9675HigJun 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A malicious WebSocket server can stream many small fragments that each pass per-frame validation but collectively exceed the…

  • CVE-2026-7250HigJun 11, 2026
    risk 0.49cvss 7.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in…

  • CVE-2026-53460HigJun 10, 2026
    risk 0.49cvss 7.5epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condition. This issue has been patched in…