Allocation of Resources Without Limits or Throttling in WeGIA - CVE-2025-27419
Published: March 2, 2025 / Updated: May 2, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the URL handling and crawling-exposed application paths when processing recursive requests for dynamically generated URLs. A remote attacker can send a large volume of crafted crawl requests to cause a denial of service.
The issue can be triggered through aggressive spidering that recursively explores dynamic URL variations and exposed static-file directories, causing the server to become unresponsive or return HTTP 5xx errors.