Executive brief
A vulnerability in the MIA Technology Pizzy Library allows an attacker to overwhelm the system with excessive requests. This can lead to a denial-of-service condition, making the affected application or service unavailable to legitimate users. Organizations using this library should update to version 1.3.9.26250 or later to ensure service stability.
Technical details
The MIA Technology Pizzy Library is vulnerable to an Improper Control of Interaction Frequency (CWE-799) flaw, commonly referred to as a flooding vulnerability. An authenticated attacker with network access can exploit this by sending a high volume of requests that the library fails to rate-limit or throttle effectively. This results in high resource consumption and a denial-of-service (DoS) impact on the availability of the host application. The issue is fixed in version 1.3.9.26250.
Affected products
- MIA Technology Inc. Pizzy Library from 1.0.0.26250 before 1.3.9.26250
Timeline
- 2026-06-15: advisory: NVD and TR-CERT published the advisory