Common Weakness Enumeration

CWE-400

Discouraged

Uncontrolled Resource Consumption

Abstraction: Class · Status: Draft

The product does not properly control the allocation and maintenance of a limited resource.

6460 vulnerabilities reference this CWE, most recent first.

GHSA-WRP8-556F-JX6R

Vulnerability from github – Published: 2022-04-30 18:10 – Updated: 2025-08-27 21:31
VLAI
Details

Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login). This applies to some IOS 9.x, 10.x, and 11.x releases.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-1999-0159"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-400"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "1998-08-12T04:00:00Z",
    "severity": "MODERATE"
  },
  "details": "Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login).  This applies to some IOS 9.x, 10.x, and 11.x releases.",
  "id": "GHSA-wrp8-556f-jx6r",
  "modified": "2025-08-27T21:31:34Z",
  "published": "2022-04-30T18:10:04Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-1999-0159"
    },
    {
      "type": "WEB",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0159"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-WRVR-8MPX-R7PP

Vulnerability from github – Published: 2018-07-20 16:20 – Updated: 2023-09-12 18:28
VLAI
Summary
mime Regular Expression Denial of Service when MIME lookup performed on untrusted user input
Details

Affected versions of mime are vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.

Recommendation

Update to version 2.0.3 or later.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "mime"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.0.0"
            },
            {
              "fixed": "2.0.3"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "npm",
        "name": "mime"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.4.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2017-16138"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-400"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T22:01:10Z",
    "nvd_published_at": null,
    "severity": "HIGH"
  },
  "details": "Affected versions of `mime` are vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.\n\n\n## Recommendation\n\nUpdate to version 2.0.3 or later.",
  "id": "GHSA-wrvr-8mpx-r7pp",
  "modified": "2023-09-12T18:28:52Z",
  "published": "2018-07-20T16:20:52Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-16138"
    },
    {
      "type": "WEB",
      "url": "https://github.com/broofa/node-mime/issues/167"
    },
    {
      "type": "WEB",
      "url": "https://github.com/broofa/mime/commit/1df903fdeb9ae7eaa048795b8d580ce2c98f40b0"
    },
    {
      "type": "WEB",
      "url": "https://github.com/broofa/mime/commit/855d0c4b8b22e4a80b9401a81f2872058eae274d"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/broofa/mime"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "mime Regular Expression Denial of Service when MIME lookup performed on untrusted user input"
}

GHSA-WV35-897X-F828

Vulnerability from github – Published: 2022-05-24 17:12 – Updated: 2022-05-24 17:12
VLAI
Details

The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusal of new authorized connections, and cause a reboot via connect and write system calls, because of uncontrolled resource management.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2020-10364"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-400"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2020-03-23T16:15:00Z",
    "severity": "MODERATE"
  },
  "details": "The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusal of new authorized connections, and cause a reboot via connect and write system calls, because of uncontrolled resource management.",
  "id": "GHSA-wv35-897x-f828",
  "modified": "2022-05-24T17:12:13Z",
  "published": "2022-05-24T17:12:13Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-10364"
    },
    {
      "type": "WEB",
      "url": "https://packetstormsecurity.com/files/156790/Microtik-SSH-Daemon-6.44.3-Denial-Of-Service.html"
    },
    {
      "type": "WEB",
      "url": "https://www.exploit-db.com/exploits/48228"
    }
  ],
  "schema_version": "1.4.0",
  "severity": []
}

GHSA-WV8Q-QHHJ-9H54

Vulnerability from github – Published: 2026-09-30 15:36 – Updated: 2026-09-30 15:36
VLAI
Summary
jackson-databind retains every unknown raw type ID
Details

Summary

With @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unknown raw type ID selects the same fallback deserializer but is retained as a separate key in TypeDeserializerBase._deserializers. An attacker who can repeatedly supply new unknown type IDs can grow this process-lifetime cache without a configured bound.

Details

The affected path is TypeDeserializerBase._findDeserializer(). After an unknown name-based type ID resolves to the configured fallback/default implementation, jackson-databind caches the result under the attacker-provided raw typeId. Although all such IDs select the same fallback deserializer, each new string remains a distinct cache key.

The behavior is runtime-confirmed in jackson-databind 2.22.1 and 3.2.1. Current 2.22 and 3.2 source branches retained the unbounded _deserializers map and per-raw-ID cache write when rechecked. The earlier affected floor has not been established, patched versions are: 2.18.11, 2.21.7, 2.22.3, 3.1.7 and 3.2.3.

The vulnerable application must enable name-based polymorphism with a defaultImpl or equivalent fallback, accept attacker-influenced type IDs, and reuse a long-lived mapper/type deserializer across requests.

Suggested correction: avoid caching each unknown raw ID when every such ID resolves to the same fallback, use a fallback sentinel, or use an explicitly bounded concurrency-safe cache. A regression should contrast many distinct unknown IDs with repetitions of one unknown ID across requests.

PoC

Configure a polymorphic base type with @JsonTypeInfo(use = JsonTypeInfo.Id.NAME, defaultImpl = Fallback.class) and deserialize inputs containing unknown type names through the same mapper. Inspect TypeDeserializerBase._deserializers after the run.

On affected 2.x and 3.x versions, 10,000 distinct unknown raw type IDs produce 10,000 retained cache entries even though every input selects the same fallback deserializer. A matched control that repeats one unknown ID 10,000 times produces one retained entry. This isolates attacker-controlled key cardinality from ordinary request count.

Impact

Where the stated polymorphic fallback configuration is exposed to attacker-influenced type IDs, distinct inputs cause incremental process-lifetime memory retention and eventual availability pressure or denial of service. This is not claimed as a single-request allocation spike, and no fixed bytes-per-ID or time-to-out-of-memory value is asserted. No confidentiality, integrity, or code-execution impact is claimed.

Requested credit: Daniel Birtwhistle

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 2.18.10"
      },
      "package": {
        "ecosystem": "Maven",
        "name": "com.fasterxml.jackson.core:jackson-databind"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.0.0"
            },
            {
              "fixed": "2.18.11"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 2.21.6"
      },
      "package": {
        "ecosystem": "Maven",
        "name": "com.fasterxml.jackson.core:jackson-databind"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.19.0"
            },
            {
              "fixed": "2.21.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 2.22.2"
      },
      "package": {
        "ecosystem": "Maven",
        "name": "com.fasterxml.jackson.core:jackson-databind"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.22.0"
            },
            {
              "fixed": "2.22.3"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 3.1.6"
      },
      "package": {
        "ecosystem": "Maven",
        "name": "tools.jackson.core:jackson-databind"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.0.0"
            },
            {
              "fixed": "3.1.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 3.2.2"
      },
      "package": {
        "ecosystem": "Maven",
        "name": "tools.jackson.core:jackson-databind"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.2.0"
            },
            {
              "fixed": "3.2.3"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-91776"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-400"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-30T15:36:55Z",
    "nvd_published_at": "2026-09-23T03:17:04Z",
    "severity": "HIGH"
  },
  "details": "### Summary\n\nWith `@JsonTypeInfo(use = Id.NAME, defaultImpl = ...)`, every distinct unknown\nraw type ID selects the same fallback deserializer but is retained as a\nseparate key in `TypeDeserializerBase._deserializers`. An attacker who can\nrepeatedly supply new unknown type IDs can grow this process-lifetime cache\nwithout a configured bound.\n\n### Details\n\nThe affected path is `TypeDeserializerBase._findDeserializer()`. After an\nunknown name-based type ID resolves to the configured fallback/default\nimplementation, jackson-databind caches the result under the attacker-provided\nraw `typeId`. Although all such IDs select the same fallback deserializer, each\nnew string remains a distinct cache key.\n\nThe behavior is runtime-confirmed in jackson-databind 2.22.1 and 3.2.1.\nCurrent 2.22 and 3.2 source branches retained the unbounded `_deserializers`\nmap and per-raw-ID cache write when rechecked. The earlier affected floor has\nnot been established, patched versions are: 2.18.11, 2.21.7, 2.22.3, 3.1.7 and 3.2.3.\n\nThe vulnerable application must enable name-based polymorphism with a\n`defaultImpl` or equivalent fallback, accept attacker-influenced type IDs, and\nreuse a long-lived mapper/type deserializer across requests.\n\nSuggested correction: avoid caching each unknown raw ID when every such ID\nresolves to the same fallback, use a fallback sentinel, or use an explicitly\nbounded concurrency-safe cache. A regression should contrast many distinct\nunknown IDs with repetitions of one unknown ID across requests.\n\n### PoC\n\nConfigure a polymorphic base type with\n`@JsonTypeInfo(use = JsonTypeInfo.Id.NAME, defaultImpl = Fallback.class)` and\ndeserialize inputs containing unknown type names through the same mapper.\nInspect `TypeDeserializerBase._deserializers` after the run.\n\nOn affected 2.x and 3.x versions, 10,000 distinct unknown raw type IDs produce\n10,000 retained cache entries even though every input selects the same\nfallback deserializer. A matched control that repeats one unknown ID 10,000\ntimes produces one retained entry. This isolates attacker-controlled key\ncardinality from ordinary request count.\n\n### Impact\n\nWhere the stated polymorphic fallback configuration is exposed to\nattacker-influenced type IDs, distinct inputs cause incremental\nprocess-lifetime memory retention and eventual availability pressure or\ndenial of service. This is not claimed as a single-request allocation spike,\nand no fixed bytes-per-ID or time-to-out-of-memory value is asserted. No\nconfidentiality, integrity, or code-execution impact is claimed.\n\nRequested credit: Daniel Birtwhistle",
  "id": "GHSA-wv8q-qhhj-9h54",
  "modified": "2026-09-30T15:36:55Z",
  "published": "2026-09-30T15:36:55Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91776"
    },
    {
      "type": "WEB",
      "url": "https://github.com/FasterXML/jackson-databind/issues/6203"
    },
    {
      "type": "WEB",
      "url": "https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/FasterXML/jackson-databind"
    },
    {
      "type": "WEB",
      "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11"
    },
    {
      "type": "WEB",
      "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7"
    },
    {
      "type": "WEB",
      "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3"
    },
    {
      "type": "WEB",
      "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7"
    },
    {
      "type": "WEB",
      "url": "https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "jackson-databind retains every unknown raw type ID "
}

GHSA-WV94-5QCP-6M36

Vulnerability from github – Published: 2026-08-25 14:34 – Updated: 2026-08-25 14:34
VLAI
Summary
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
Details

Summary

The PraisonAI MCP HTTP-stream server creates a new in-memory session on every initialize request and never removes it. The cleanup routine that would expire sessions (_cleanup_sessions) is defined but never called anywhere in the codebase, and the configured session TTL is never enforced. There is no cap on the number of sessions. Because initialize requires no authentication and the server keeps every session dictionary forever, an attacker who can reach the endpoint (directly when the server is bound to a routable address, or from a victim's browser via the separate Origin-validation bypass) can drive memory usage up without bound until the process is killed by the out-of-memory killer. The same unbounded-growth pattern also applies to the cancelled-requests set populated by notifications/cancelled.

Details

In transports/http_stream.py, each initialize creates and stores a session with no limit:

if body.get("method") == "initialize":
    new_session_id = str(uuid.uuid4())
    self._sessions[new_session_id] = {
        "created_at": time.time(),
        "last_activity": time.time(),
    }

A cleanup method exists:

def _cleanup_sessions(self) -> None:
    now = time.time()
    expired = [sid for sid, data in self._sessions.items()
               if now - data["last_activity"] > self.session_ttl]
    for sid in expired:
        del self._sessions[sid]

but grep across the package shows it has no call sites: it is never invoked on a timer, on request handling, or from any background task. self.session_ttl (default 3600) is stored and otherwise unused. There is no maximum-session check anywhere on the write path. As a result self._sessions grows monotonically for the lifetime of the process.

initialize is unauthenticated: in mcp_post the API-key check is skipped when no key is configured (the default), and initialize does not require a prior session. The Origin check is the only gate, and a request with no Origin header is allowed; additionally the Origin allowlist is bypassable (see the companion report on the startswith Origin-validation bypass), so the endpoint is reachable from a malicious web page as well as directly.

The server-side cancellation set in server.py has the same defect:

if method == "notifications/cancelled":
    request_id = params.get("requestId")
    if request_id:
        self._cancelled_requests.add(str(request_id))   # never cleared

self._cancelled_requests is an unbounded set that is added to but never pruned.

PoC

scripts/poc_mcp_session_dos.sh. Start the server (default config, no API key):

praisonai mcp serve --transport http-stream --host 127.0.0.1 --port 8080

Send repeated initialize requests and watch the active session count grow:

for i in $(seq 1 200); do
  curl -s -o /dev/null -X POST http://127.0.0.1:8080/mcp \
    -H 'Content-Type: application/json' -H 'Origin: http://localhost' \
    -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"x","version":"1"}}}'
done
curl -s http://127.0.0.1:8080/health

Observed on 4.6.52 after 200 requests:

{"status":"healthy","server":"praisonai","version":"1.0.0","protocol_version":"2025-11-25","active_sessions":200}

The count rises by one per request and never decreases; there is no TTL expiry and no cap. Sustained requests grow the process resident set without bound. Each session also retains any SSE event history keyed by session id, amplifying the per-session footprint.

Impact

An unauthenticated client can exhaust the memory of the host running the MCP server, leading to denial of service (the process is terminated by the OOM killer, taking down the agent endpoint). When the server is bound to a routable interface (for example --host 0.0.0.0, common in containers), this is a direct remote unauthenticated DoS. With the default localhost bind, it is reachable from any web page the operator visits, because initialize is unauthenticated and the Origin gate is bypassable. The defect is a missing cleanup wiring plus the absence of any session cap, so it manifests even under benign long-running use.

Remediation

Enforce the session TTL and cap the number of concurrent sessions: call _cleanup_sessions periodically (a background asyncio task, or opportunistically on each request) and reject new sessions with a 429/503 once a configurable maximum is reached. Bound _cancelled_requests similarly (for example an LRU or a periodic prune keyed by age), since it is also never cleared. Require authentication by default on the HTTP-stream transport so that anonymous clients cannot create sessions at all.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "PraisonAI"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4.6.58"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-55531"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-400",
      "CWE-770"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-08-25T14:34:28Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
  },
  "details": "### Summary\n\nThe PraisonAI MCP HTTP-stream server creates a new in-memory session on every initialize request and never removes it. The cleanup routine that would expire sessions (_cleanup_sessions) is defined but never called anywhere in the codebase, and the configured session TTL is never enforced. There is no cap on the number of sessions. Because initialize requires no authentication and the server keeps every session dictionary forever, an attacker who can reach the endpoint (directly when the server is bound to a routable address, or from a victim\u0027s browser via the separate Origin-validation bypass) can drive memory usage up without bound until the process is killed by the out-of-memory killer. The same unbounded-growth pattern also applies to the cancelled-requests set populated by notifications/cancelled.\n\n### Details\n\nIn transports/http_stream.py, each initialize creates and stores a session with no limit:\n\n```python\nif body.get(\"method\") == \"initialize\":\n    new_session_id = str(uuid.uuid4())\n    self._sessions[new_session_id] = {\n        \"created_at\": time.time(),\n        \"last_activity\": time.time(),\n    }\n```\n\nA cleanup method exists:\n\n```python\ndef _cleanup_sessions(self) -\u003e None:\n    now = time.time()\n    expired = [sid for sid, data in self._sessions.items()\n               if now - data[\"last_activity\"] \u003e self.session_ttl]\n    for sid in expired:\n        del self._sessions[sid]\n```\n\nbut grep across the package shows it has no call sites: it is never invoked on a timer, on request handling, or from any background task. self.session_ttl (default 3600) is stored and otherwise unused. There is no maximum-session check anywhere on the write path. As a result self._sessions grows monotonically for the lifetime of the process.\n\ninitialize is unauthenticated: in mcp_post the API-key check is skipped when no key is configured (the default), and initialize does not require a prior session. The Origin check is the only gate, and a request with no Origin header is allowed; additionally the Origin allowlist is bypassable (see the companion report on the startswith Origin-validation bypass), so the endpoint is reachable from a malicious web page as well as directly.\n\nThe server-side cancellation set in server.py has the same defect:\n\n```python\nif method == \"notifications/cancelled\":\n    request_id = params.get(\"requestId\")\n    if request_id:\n        self._cancelled_requests.add(str(request_id))   # never cleared\n```\n\nself._cancelled_requests is an unbounded set that is added to but never pruned.\n\n### PoC\n\nscripts/poc_mcp_session_dos.sh. Start the server (default config, no API key):\n\n```\npraisonai mcp serve --transport http-stream --host 127.0.0.1 --port 8080\n```\n\nSend repeated initialize requests and watch the active session count grow:\n\n```bash\nfor i in $(seq 1 200); do\n  curl -s -o /dev/null -X POST http://127.0.0.1:8080/mcp \\\n    -H \u0027Content-Type: application/json\u0027 -H \u0027Origin: http://localhost\u0027 \\\n    -d \u0027{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"initialize\",\"params\":{\"protocolVersion\":\"2025-06-18\",\"capabilities\":{},\"clientInfo\":{\"name\":\"x\",\"version\":\"1\"}}}\u0027\ndone\ncurl -s http://127.0.0.1:8080/health\n```\n\nObserved on 4.6.52 after 200 requests:\n\n```\n{\"status\":\"healthy\",\"server\":\"praisonai\",\"version\":\"1.0.0\",\"protocol_version\":\"2025-11-25\",\"active_sessions\":200}\n```\n\nThe count rises by one per request and never decreases; there is no TTL expiry and no cap. Sustained requests grow the process resident set without bound. Each session also retains any SSE event history keyed by session id, amplifying the per-session footprint.\n\n### Impact\n\nAn unauthenticated client can exhaust the memory of the host running the MCP server, leading to denial of service (the process is terminated by the OOM killer, taking down the agent endpoint). When the server is bound to a routable interface (for example --host 0.0.0.0, common in containers), this is a direct remote unauthenticated DoS. With the default localhost bind, it is reachable from any web page the operator visits, because initialize is unauthenticated and the Origin gate is bypassable. The defect is a missing cleanup wiring plus the absence of any session cap, so it manifests even under benign long-running use.\n\n### Remediation\n\nEnforce the session TTL and cap the number of concurrent sessions: call _cleanup_sessions periodically (a background asyncio task, or opportunistically on each request) and reject new sessions with a 429/503 once a configurable maximum is reached. Bound _cancelled_requests similarly (for example an LRU or a periodic prune keyed by age), since it is also never cleared. Require authentication by default on the HTTP-stream transport so that anonymous clients cannot create sessions at all.",
  "id": "GHSA-wv94-5qcp-6m36",
  "modified": "2026-08-25T14:34:28Z",
  "published": "2026-08-25T14:34:28Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-wv94-5qcp-6m36"
    },
    {
      "type": "WEB",
      "url": "https://github.com/MervinPraison/PraisonAI/commit/2f9677abb2ea68eab864ee8b6a828fd0141612e1"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/MervinPraison/PraisonAI"
    },
    {
      "type": "WEB",
      "url": "https://github.com/MervinPraison/PraisonAI/releases/tag/v4.6.58"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)"
}

GHSA-WV97-3Q88-X27X

Vulnerability from github – Published: 2025-07-14 09:31 – Updated: 2025-07-14 09:31
VLAI
Details

A vulnerability was found in chinese-poetry 0.1. It has been rated as problematic. This issue affects some unknown processing of the file rank/server.js. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-7579"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-400"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-07-14T07:15:24Z",
    "severity": "MODERATE"
  },
  "details": "A vulnerability was found in chinese-poetry 0.1. It has been rated as problematic. This issue affects some unknown processing of the file rank/server.js. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.",
  "id": "GHSA-wv97-3q88-x27x",
  "modified": "2025-07-14T09:31:03Z",
  "published": "2025-07-14T09:31:03Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-7579"
    },
    {
      "type": "WEB",
      "url": "https://github.com/chinese-poetry/chinese-poetry/issues/396"
    },
    {
      "type": "WEB",
      "url": "https://github.com/chinese-poetry/chinese-poetry/issues/396#issue-3204562392"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/?ctiid.316277"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/?id.316277"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/?submit.609704"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-WVCQ-2RCQ-FQC9

Vulnerability from github – Published: 2026-09-03 06:30 – Updated: 2026-09-03 06:30
VLAI
Details

A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageData of the file gui_agents/s1/utils/ocr_server.py of the component OCR HTTP API. Executing a manipulation of the argument img_bytes can lead to resource consumption. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-84886"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-400"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-09-03T05:16:47Z",
    "severity": "MODERATE"
  },
  "details": "A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageData of the file gui_agents/s1/utils/ocr_server.py of the component OCR HTTP API. Executing a manipulation of the argument img_bytes can lead to resource consumption. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.",
  "id": "GHSA-wvcq-2rcq-fqc9",
  "modified": "2026-09-03T06:30:22Z",
  "published": "2026-09-03T06:30:22Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84886"
    },
    {
      "type": "WEB",
      "url": "https://github.com/hackerguopeng/cve/tree/main/AgentS_OCR_HTTP_Body_Image_DoS_Report"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/cve/CVE-2026-84886"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/submit/886443"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/vuln/398135"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/vuln/398135/cti"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-WVGJ-PJC7-8FC4

Vulnerability from github – Published: 2022-05-24 19:19 – Updated: 2022-05-24 19:19
VLAI
Details

A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2021-39914"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-400",
      "CWE-770"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2021-11-04T23:15:00Z",
    "severity": "MODERATE"
  },
  "details": "A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user",
  "id": "GHSA-wvgj-pjc7-8fc4",
  "modified": "2022-05-24T19:19:55Z",
  "published": "2022-05-24T19:19:55Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-39914"
    },
    {
      "type": "WEB",
      "url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39914.json"
    },
    {
      "type": "WEB",
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/289948"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-WVGW-2RWH-W596

Vulnerability from github – Published: 2023-12-12 12:30 – Updated: 2024-10-08 21:31
VLAI
Details

Denial-of-service (DoS) vulnerability exists in commplex-link service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-49140"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-400"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-12-12T10:15:10Z",
    "severity": "HIGH"
  },
  "details": "Denial-of-service (DoS) vulnerability exists in commplex-link service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packets to specific ports, a denial-of-service (DoS) condition may occur.",
  "id": "GHSA-wvgw-2rwh-w596",
  "modified": "2024-10-08T21:31:05Z",
  "published": "2023-12-12T12:30:51Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49140"
    },
    {
      "type": "WEB",
      "url": "https://jvn.jp/en/jp/JVN34145838"
    },
    {
      "type": "WEB",
      "url": "https://www.electronics.jtekt.co.jp/en/topics/202312116562"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-WVH2-2VCC-8H4X

Vulnerability from github – Published: 2022-05-24 19:16 – Updated: 2022-07-13 00:01
VLAI
Details

Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources via the /enginemanager/server/vhost/historical.jsdata vhost parameter. This is due to the insufficient management of available filesystem resources. An attacker could exploit this vulnerability through the Virtual Host Monitoring section by requesting random virtual-host historical data and exhausting available filesystem resources. A successful exploit could allow the attacker to cause database errors and cause the device to become unresponsive to web-based management. (Manual intervention is required to free filesystem resources and return the application to an operational state.)

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2021-35492"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-400"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2021-10-05T16:15:00Z",
    "severity": "MODERATE"
  },
  "details": "Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources via the /enginemanager/server/vhost/historical.jsdata vhost parameter. This is due to the insufficient management of available filesystem resources. An attacker could exploit this vulnerability through the Virtual Host Monitoring section by requesting random virtual-host historical data and exhausting available filesystem resources. A successful exploit could allow the attacker to cause database errors and cause the device to become unresponsive to web-based management. (Manual intervention is required to free filesystem resources and return the application to an operational state.)",
  "id": "GHSA-wvh2-2vcc-8h4x",
  "modified": "2022-07-13T00:01:28Z",
  "published": "2022-05-24T19:16:32Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-35492"
    },
    {
      "type": "WEB",
      "url": "https://n4nj0.github.io/advisories/wowza-streaming-engine-i"
    },
    {
      "type": "WEB",
      "url": "https://www.gruppotim.it/redteam"
    },
    {
      "type": "WEB",
      "url": "https://www.wowza.com/docs/wowza-streaming-engine-4-8-14-release-notes"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

Mitigation
Architecture and Design

Design throttling mechanisms into the system architecture. The best protection is to limit the amount of resources that an unauthorized user can cause to be expended. A strong authentication and access control model will help prevent such attacks from occurring in the first place. The login application should be protected against DoS attacks as much as possible. Limiting the database access, perhaps by caching result sets, can help minimize the resources expended. To further limit the potential for a DoS attack, consider tracking the rate of requests received from users and blocking requests that exceed a defined rate threshold.

Mitigation
Architecture and Design
  • Mitigation of resource exhaustion attacks requires that the target system either:
  • The first of these solutions is an issue in itself though, since it may allow attackers to prevent the use of the system by a particular valid user. If the attacker impersonates the valid user, they may be able to prevent the user from accessing the server in question.
  • The second solution is simply difficult to effectively institute -- and even when properly done, it does not provide a full solution. It simply makes the attack require more resources on the part of the attacker.
  • recognizes the attack and denies that user further access for a given amount of time, or
  • uniformly throttles all requests in order to make it more difficult to consume resources more quickly than they can again be freed.
Mitigation
Architecture and Design

Ensure that protocols have specific limits of scale placed on them.

Mitigation
Implementation

Ensure that all failures in resource allocation place the system into a safe posture.

CAPEC-147: XML Ping of the Death

An attacker initiates a resource depletion attack where a large number of small XML messages are delivered at a sufficiently rapid rate to cause a denial of service or crash of the target. Transactions such as repetitive SOAP transactions can deplete resources faster than a simple flooding attack because of the additional resources used by the SOAP protocol and the resources necessary to process SOAP messages. The transactions used are immaterial as long as they cause resource utilization on the target. In other words, this is a normal flooding attack augmented by using messages that will require extra processing on the target.

CAPEC-227: Sustained Client Engagement

An adversary attempts to deny legitimate users access to a resource by continually engaging a specific resource in an attempt to keep the resource tied up as long as possible. The adversary's primary goal is not to crash or flood the target, which would alert defenders; rather it is to repeatedly perform actions or abuse algorithmic flaws such that a given resource is tied up and not available to a legitimate user. By carefully crafting a requests that keep the resource engaged through what is seemingly benign requests, legitimate users are limited or completely denied access to the resource.

CAPEC-492: Regular Expression Exponential Blowup

An adversary may execute an attack on a program that uses a poor Regular Expression(Regex) implementation by choosing input that results in an extreme situation for the Regex. A typical extreme situation operates at exponential time compared to the input size. This is due to most implementations using a Nondeterministic Finite Automaton(NFA) state machine to be built by the Regex algorithm since NFA allows backtracking and thus more complex regular expressions.