CWE-406Class1 in KEV

Insufficient Control of Network Message Volume (Network Amplification)

Incomplete in the CWE catalog · 16 CVEs mapped

16
CVEs mapped
1
In KEV
7.5
Median CVSS
What it is

The product does not sufficiently monitor or control transmitted network traffic volume, so that an actor can cause the product to transmit more traffic than should be allowed for that actor.

Recent examples
6.5cvss
CVE-2026-68080

CVE-2026-68080 - MEDIUM Severity Vulnerability

It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.

MEDIUMno explanation yet
0%
epss
8.6cvss
CVE-2026-54609

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and cause a denial of service on the host. No fixed version is available as of this review.

HIGHno explanation yet
0%
epss
5.3cvss
CVE-2026-50045

'max-global-quota' reset by DNSSEC validation restarts

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security configuration that limits upstream amplification traffic.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-406
Abstraction
Class
Structure
Simple
Status
Incomplete