CVE-2026-27695: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-27695 is a resource exhaustion vulnerability in zae-limiter, a Python rate limiting library using the token bucket algorithm backed by AWS DynamoDB. All rate limit buckets for a single entity share the same DynamoDB partition key (namespace/ENTITY#{id}), allowing a high-traffic entity to exceed DynamoDB's per-partition throughput limits (~1,000 WCU/sec) and cause service throttling. All versions up to and including 0.10.0 are affected; version 0.10.1 contains the fix. The vulnerability was published on February 23, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) per the official advisory, or 5.3 (Medium) per NVD (Github Advisory, GitHub Security Advisory).

Technical details

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling). Each acquire() call performs a TransactWriteItems or UpdateItem operation against DynamoDB items that all share the same partition key, meaning all write capacity for a given entity is concentrated in a single DynamoDB partition. For cascade entities, this doubles to 2–4 writes per request (child + parent). At sustained rates above approximately 500 req/sec for a single entity, DynamoDB's adaptive capacity cannot redistribute fast enough, triggering ProvisionedThroughputExceededException. The library provides no built-in mitigations such as partition key sharding/salting, write coalescing, batching, or client-side admission control (Github Advisory, GitHub Security Advisory).

Impact

Exploitation results in a denial-of-service condition limited to availability — there is no confidentiality or integrity impact. High-traffic entities experience elevated latency and rejected requests beyond what their configured rate limits specify, and other entities co-located in the same DynamoDB partition may suffer collateral throttling. In multi-tenant deployments such as shared LLM proxy scenarios, one tenant's burst traffic can degrade service availability for other tenants, creating a fairness and availability risk across the entire shared instance (Github Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039–0.061%, placing it in the 19th percentile for exploitation probability within 30 days. Exploitation requires low privileges (an authenticated user with access to the rate-limited service) and no user interaction, but the attack is constrained to availability impact only.

Exploitation steps

  1. Identify target: Locate a service using zae-limiter version ≤ 0.10.0 with DynamoDB as its backend, particularly multi-tenant deployments (e.g., shared LLM proxies) where multiple entities share the same DynamoDB table.
  2. Obtain low-privilege access: Authenticate to the target service with any valid low-privilege account or API key that allows making rate-limited requests.
  3. Configure a high-limit entity: Identify or create an entity with high rate limits (e.g., 100,000 requests per minute), which concentrates all write operations under a single DynamoDB partition key (namespace/ENTITY#{id}).
  4. Generate sustained high-traffic: Send sustained traffic at 1,000+ req/sec to the target entity, causing all acquire() calls to hammer the same DynamoDB partition with TransactWriteItems or UpdateItem operations.
  5. Trigger throttling: DynamoDB's adaptive capacity fails to redistribute fast enough, causing ProvisionedThroughputExceededException and RateLimiterUnavailable exceptions for the targeted entity and co-located entities in the same partition.
  6. Observe impact: Monitor DynamoDB ThrottledRequests CloudWatch metrics increasing; affected entities experience latency spikes and rejected requests beyond their configured rate limits (GitHub Security Advisory).

Indicators of compromise

  • AWS CloudWatch Metrics: Spike in DynamoDB ThrottledRequests metric for the table used by zae-limiter; elevated ConsumedWriteCapacityUnits concentrated on a single partition key prefix (namespace/ENTITY#{id}).
  • Application Logs: Frequent RateLimiterUnavailable exceptions in application logs; ProvisionedThroughputExceededException errors returned from DynamoDB calls within the zae-limiter library.
  • Performance: Sudden increase in acquire() call latency for one or more entities; requests being rejected at rates inconsistent with configured rate limits.
  • Network: Unusually high and sustained request rates (1,000+ req/sec) from a single entity or client to the rate-limited service endpoint (GitHub Security Advisory).

Mitigation and workarounds

Upgrade zae-limiter to version 0.10.1 or later, which implements a pre-sharded bucket design moving buckets to per-shard partition keys (PK={ns}/BUCKET#{entity}#{resource}#{shard}) with shard doubling (1→2→4→8) triggered on WCU exhaustion. No configuration-based workaround is available in versions ≤ 0.10.0, as the library lacks built-in partition key sharding, write coalescing, or client-side admission control. Organizations should audit all deployments of zae-limiter and prioritize upgrading, particularly in multi-tenant environments (Github Advisory, v0.10.1 Release).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management