Skip to main content

Threats Tagged 'cwe-1050'

View all threats tagged with 'cwe-1050'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-1050

Threats Tagged 'cwe-1050'

Click on any threat for detailed analysis and mitigation recommendations

If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

Join the discussion

A vulnerability in thephpleague commonmark PHP library versions from 0.6.0 up to but not including 2.9.0 allows specially crafted Markdown input to cause quadratic time complexity during parsing. This inefficient algorithmic complexity can lead to disproportionate CPU consumption, resulting in a denial of service condition. The issue is resolved in version 2.9.0.

Join the discussion

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, and 8.21.0.

Join the discussion

This update includes the following RPMs: unbound: * python3-unbound-1.25.1-2.hum1 (aarch64, x86_64) * unbound-1.25.1-2.hum1 (aarch64, x86_64) * unbound-anchor-1.25.1-2.hum1 (aarch64, x86_64) * unbound-devel-1.25.1-2.hum1 (aarch64, x86_64) * unbound-dracut-1.25.1-2.hum1 (aarch64, x86_64) * unbound-libs-1.25.1-2.hum1 (aarch64, x86_64) * unbound-munin-1.25.1-2.hum1 (noarch) * unbound-utils-1.25.1-2.hum1 (aarch64, x86_64) * unbound-1.25.1-2.hum1.src (src)

Join the discussion

NLnet Labs Unbound versions up to and including 1.25.0 contain a vulnerability related to inefficient algorithmic complexity in handling DNS replies with very large resource record sets (RRsets). This flaw can cause Unbound to spend excessive time applying name compression, potentially leading to degraded performance or denial of service. The issue arises when records do not share a suffix above the root, causing an unbounded operation in name compression. A fix was introduced in version 1.25.1 that correctly increments the compression counter regardless of compression tree lookup results, addressing this vulnerability.

Join the discussion

Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in http1 headers parsing can lead to slowdown over multiple packets. Version 8.0.3 patches the issue. No known workarounds are available.

Join the discussion

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficiencies in xff handling, especially for alerts not triggered in a tx, can lead to severe slowdowns. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, disable XFF support in the eve configuration. The setting is disabled by default.

Join the discussion

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `sanitizeArg` - this is the same action but an alias) is vulnerable to adding an excessive number of arguments, thereby leading to denial of service. Version 2.9.10 fixes the issue. As a workaround, avoid using rules that contain the `sanitiseArg` (or `sanitizeArg`) action.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Tag: cwe-1050
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses