---
id: CVE-2022-21822
aliases:
  - GHSA-jx8f-cpx7-fv47
  - PYSEC-2026-695
title: Allocation of Resources Without Limits or Throttling in nvflare
summary: Allocation of Resources Without Limits or Throttling in nvflare
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: nvflare
product: nvflare
ecosystem: pip
affected:
  - nvflare < 2.0.16
patched:
  - nvflare 2.0.16
published: '2022-03-18'
updated: '2026-07-08'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-jx8f-cpx7-fv47'
references:
  - url: 'https://github.com/NVIDIA/NVFlare/security/advisories/GHSA-jx8f-cpx7-fv47'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-21822'
  - url: 'https://github.com/NVIDIA/NVFlare'
tags:
  - osv
  - pip
epss: 0.01067
epssPercentile: 0.63276
ingestedAt: '2026-07-08T18:25:50.905Z'
---

## Overview

### Impact
NVIDIA FLARE contains a vulnerability in Admin Interface, where an un-authorized attacker can cause Allocation of Resources Without Limits or Throttling, which may lead to cause system unavailable

All versions before 2.0.16 are affected.

### Patches
The patch will be included in nvflare==2.0.16.

### Workarounds
The changes in commits https://github.com/NVIDIA/NVFlare/commit/93588b3a0dff9bd4568983071b74d8b420de3a6e and https://github.com/NVIDIA/NVFlare/commit/93588b3a0dff9bd4568983071b74d8b420de3a6e  can be applied to any version of the NVIDIA FLARE without any adverse effect.

### Additional information
Issue Found on: 2022.3.3
Issue Found by: Oliver Sellwood (@Nintorac)

## Affected packages

- `nvflare < 2.0.16`

## Remediation

Upgrade to a patched release:

- `nvflare 2.0.16`
