VYPR

CWE-770

Allocation of Resources Without Limits or Throttling

BaseIncompleteLikelihood: High

Description

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-147 · CAPEC-197 · CAPEC-229 · CAPEC-230 · CAPEC-231 · CAPEC-469 · CAPEC-482 · CAPEC-486 · CAPEC-487 · CAPEC-488 · CAPEC-489 · CAPEC-490 · CAPEC-491 · CAPEC-493 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-528

CVEs mapped to this weakness (2,224)

page 90 of 112
  • CVE-2026-22917MedJan 15, 2026
    risk 0.28cvss 4.3epss 0.01

    Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service.

  • CVE-2025-64422MedJan 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertises a rate limit of 5 requests but can be trivially bypassed by rotating the X-Forwarded-For header.…

  • CVE-2025-41693MedDec 9, 2025
    risk 0.28cvss 4.3epss 0.01

    A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays open and uses resources which leads to a reduced performance of the management functions. Switching functionality is not affected.

  • CVE-2025-54320MedNov 18, 2025
    risk 0.28cvss 4.3epss 0.00

    In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating invite requests.

  • CVE-2025-2934MedOct 9, 2025
    risk 0.28cvss 4.3epss 0.01

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that could have allowed an authenticated attacker to create a denial of service condition by configuring malicious webhook endpoints…

  • CVE-2025-11042MedSep 26, 2025
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while using…

  • CVE-2025-7070MedJul 4, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component MFA Pairing Request Handler. The manipulation leads to allocation of resources. The attack needs to be…

  • CVE-2025-52917MedJun 21, 2025
    risk 0.28cvss 4.3epss 0.00

    The Yealink RPS API before 2025-05-26 lacks rate limiting, potentially enabling information disclosure via excessive requests.

  • CVE-2025-4432MedMay 9, 2025
    risk 0.28cvss 5.3epss 0.01

    A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32…

  • CVE-2024-51461MedApr 11, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM QRadar WinCollect Agent 10.0 through 10.1.13 could allow a remote attacker to cause a denial of service by interrupting an HTTP request that could consume memory resources.

  • CVE-2024-10307MedMar 28, 2025
    risk 0.28cvss 4.3epss 0.00

    An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A maliciously crafted file can cause uncontrolled CPU consumption when viewing the associated merge request.

  • CVE-2025-27795MedMar 7, 2025
    risk 0.28cvss 4.3epss 0.00

    ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.

  • CVE-2023-51310MedFeb 20, 2025
    risk 0.28cvss 4.3epss 0.00

    A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail…

  • CVE-2023-51309MedFeb 20, 2025
    risk 0.28cvss 4.3epss 0.00

    A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

  • CVE-2024-38316MedFeb 5, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

  • CVE-2024-56332MedJan 3, 2025
    risk 0.28cvss 5.3epss 0.01

    Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, Next.js is vulnerable to a Denial of Service (DoS) attack that allows attackers to construct requests that leaves requests to…

  • CVE-2024-45338MedDec 18, 2024
    risk 0.28cvss 5.3epss 0.01

    An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.

  • CVE-2024-9367MedDec 12, 2024
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing…

  • CVE-2024-4311MedNov 14, 2024
    risk 0.28cvss 5.4epss 0.00

    zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password change function. An attacker can brute-force the current password in the 'Update Password' function, allowing them to take over the user's account. This…

  • CVE-2024-21994MedNov 8, 2024
    risk 0.28cvss 4.3epss 0.00

    StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead to a service crash.