CWE-799: Improper Control of Interaction Frequency

What is CWE-799?

The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.

Analyzing data...

Data statistics

OWASP TOP 10:2025 RANK6 — A06:2025 — Insecure Design
RELATED CVES (365 DAYS)14
ABSTRACTIONClass

Vulnerabilities mapped to CWE-799

14 vulnerabilities1,300% increase year over year

Vulnerabilities in CISA KEV for CWE-799

0 vulnerabilities

Official definition

ByMitre CWE

The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.

This can allow the actor to perform actions more frequently than expected. The actor could be a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic (such as limiting humans to a single vote), or other consequences. For example, an authentication routine might not limit the number of times an attacker can guess a password. Or, a web site might conduct a poll but only expect humans to vote a maximum of once a day.

Characteristics

Alternate terms

  • Insufficient anti-automation — The term "insufficient anti-automation" focuses primarly on non-human actors such as viruses or bots, but the scope of this CWE entry is broader.
  • Brute force — Vulnerabilities that can be targeted using brute force attacks are often symptomatic of this weakness.

Modes of introduction

  • Architecture and Design
  • Implementation
  • Operation

Common consequences

ImpactScopeExplanation
DoS: Resource Consumption (Other), Bypass Protection Mechanism, OtherAvailability, Access Control, Other—

Representative vulnerabilities

Sources (3)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan