
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27695 is a resource exhaustion vulnerability in zae-limiter, a Python rate limiting library using the token bucket algorithm backed by AWS DynamoDB. All rate limit buckets for a single entity share the same DynamoDB partition key (namespace/ENTITY#{id}), allowing a high-traffic entity to exceed DynamoDB's per-partition throughput limits (~1,000 WCU/sec) and cause service throttling. All versions up to and including 0.10.0 are affected; version 0.10.1 contains the fix. The vulnerability was published on February 23, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) per the official advisory, or 5.3 (Medium) per NVD (Github Advisory, GitHub Security Advisory).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling). Each acquire() call performs a TransactWriteItems or UpdateItem operation against DynamoDB items that all share the same partition key, meaning all write capacity for a given entity is concentrated in a single DynamoDB partition. For cascade entities, this doubles to 2–4 writes per request (child + parent). At sustained rates above approximately 500 req/sec for a single entity, DynamoDB's adaptive capacity cannot redistribute fast enough, triggering ProvisionedThroughputExceededException. The library provides no built-in mitigations such as partition key sharding/salting, write coalescing, batching, or client-side admission control (Github Advisory, GitHub Security Advisory).
Exploitation results in a denial-of-service condition limited to availability — there is no confidentiality or integrity impact. High-traffic entities experience elevated latency and rejected requests beyond what their configured rate limits specify, and other entities co-located in the same DynamoDB partition may suffer collateral throttling. In multi-tenant deployments such as shared LLM proxy scenarios, one tenant's burst traffic can degrade service availability for other tenants, creating a fairness and availability risk across the entire shared instance (Github Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039–0.061%, placing it in the 19th percentile for exploitation probability within 30 days. Exploitation requires low privileges (an authenticated user with access to the rate-limited service) and no user interaction, but the attack is constrained to availability impact only.
zae-limiter version ≤ 0.10.0 with DynamoDB as its backend, particularly multi-tenant deployments (e.g., shared LLM proxies) where multiple entities share the same DynamoDB table.namespace/ENTITY#{id}).acquire() calls to hammer the same DynamoDB partition with TransactWriteItems or UpdateItem operations.ProvisionedThroughputExceededException and RateLimiterUnavailable exceptions for the targeted entity and co-located entities in the same partition.ThrottledRequests CloudWatch metrics increasing; affected entities experience latency spikes and rejected requests beyond their configured rate limits (GitHub Security Advisory).ThrottledRequests metric for the table used by zae-limiter; elevated ConsumedWriteCapacityUnits concentrated on a single partition key prefix (namespace/ENTITY#{id}).RateLimiterUnavailable exceptions in application logs; ProvisionedThroughputExceededException errors returned from DynamoDB calls within the zae-limiter library.acquire() call latency for one or more entities; requests being rejected at rates inconsistent with configured rate limits.Upgrade zae-limiter to version 0.10.1 or later, which implements a pre-sharded bucket design moving buckets to per-shard partition keys (PK={ns}/BUCKET#{entity}#{resource}#{shard}) with shard doubling (1→2→4→8) triggered on WCU exhaustion. No configuration-based workaround is available in versions ≤ 0.10.0, as the library lacks built-in partition key sharding, write coalescing, or client-side admission control. Organizations should audit all deployments of zae-limiter and prioritize upgrading, particularly in multi-tenant environments (Github Advisory, v0.10.1 Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."