WhisperX tag archive

#CWE-770

This page collects WhisperX intelligence signals tagged #CWE-770. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-03-30 10:27:25 · GitHub Issues

1. MEDIUM: Broker Endpoints Lack Rate Limiting, Exposing System to Local Flood Attacks

A critical security misconfiguration leaves a broker's endpoints completely unprotected against rate-limiting attacks. The vulnerability, classified as MEDIUM severity, stems from an absence of resource throttling, allowing a local attacker to flood the broker and potentially disrupt its operations. This flaw maps dire...

The Lab · 2026-05-06 18:31:45 · GitHub Issues

2. Express Middleware Vulnerability Exposes API to Uncontrolled Resource Consumption via Unbounded Body Parsing

A medium-severity security vulnerability has been identified in the application's Express body parser middleware configuration. The issue, classified under CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-400 (Uncontrolled Resource Consumption), stems from the middleware relying on default size li...