CWE-406: Network Amplification
The product does not sufficiently monitor or control transmitted network traffic volume, so that an actor can cause the product to transmit more traffic than should be allowed for that actor.
17 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-54609 — QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
- CVE-2026-45557 — Technitium DNS Server excessive DNSSEC requests
- CVE-2026-68080 — Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service
- CVE-2025-58066 — DoS Vulnerability in ntpd-rs
- CVE-2026-86202 — PocketMine-MP before 5.39.2 Network Amplification via ActorEventPacket
- CVE-2026-50045 — 'max-global-quota' reset by DNSSEC validation restarts
Recently published
- CVE-2026-86202 — PocketMine-MP before 5.39.2 Network Amplification via ActorEventPacket
- CVE-2026-68080 — Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service
- CVE-2026-54609 — QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
- CVE-2026-50045 — 'max-global-quota' reset by DNSSEC validation restarts
- CVE-2026-45557 — Technitium DNS Server excessive DNSSEC requests
- CVE-2025-58066 — DoS Vulnerability in ntpd-rs