Compliance Node Overview
MITRE CAPEC-491 (Quadratic Data Expansion) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits macro-like substitution to cause a denial of service situation due to excessive memory being allocated to fully expand the data. The result of this denial of service could cause the application to freeze or crash. This involves defining a very large entity and using it multiple times in a single entity substitution. Likelihood of attack: Unknown. Maps to weaknesses CWE-770.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/491.html
SHA-256 integrity: fb09aa99db9588a6e12fdc536235bc5d46c8f8241e7dd4d2a5b74749581dce28
Primary Citations — 7 traced to source
- MITRE CAPEC-491: Quadratic Data Expansion (https://capec.mitre.org/data/definitions/491.html)
- CWE-770: underlying weakness (http://cwe.mitre.org/data/definitions/770.html)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.