VYPR

CWE-770

Allocation of Resources Without Limits or Throttling

BaseIncompleteLikelihood: High

Description

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528

CVEs mapped to this weakness (2,258)

page 9 of 113
  • CVE-2026-73062HigAug 16, 2026
    risk 0.49cvss 7.5epss 0.00

    Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multiplier in a template to force…

  • CVE-2026-73635HigAug 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the framework's internal…

  • CVE-2026-17199HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to unbounded resource allocation.

  • CVE-2026-48702HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file into in-memory buffers without bounding the…

  • CVE-2026-71469HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. This can lead to memory…

  • CVE-2026-17271HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size.

  • CVE-2025-41770HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.

  • CVE-2026-48809HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An…

  • CVE-2026-48802HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when…

  • CVE-2026-54113HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.01

    Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.

  • CVE-2026-15561HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

  • CVE-2026-18618HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit these vulnerabilities by sending…

  • CVE-2026-15972HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors, goroutines, and memory by…

  • CVE-2026-54225HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no default placed on this size, meaning that a denial of service attack is possible if the user doesn't explicitly set the limit.…

  • CVE-2026-18649HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a…

  • CVE-2026-67592HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to…

  • CVE-2026-68074HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.

  • CVE-2026-68060HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.

  • CVE-2026-67588HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.

  • CVE-2026-67465HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.