CWE-1088: Synchronous Access of Remote Resource without Timeout
The code has a synchronous call to a remote resource, but there is no timeout for the call, or the timeout is set to infinite.
6 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-81520 — MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhaustion
- CVE-2024-12777 — Denial of Service in aimhubio/aim
- CVE-2025-4656 — Vault Vulnerable to Recovery Key Cancellation Denial of Service
Recently published
- CVE-2026-81520 — MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhaustion
- CVE-2025-4656 — Vault Vulnerable to Recovery Key Cancellation Denial of Service
- CVE-2024-12777 — Denial of Service in aimhubio/aim