NRDAX-T0333 - Unbounded Subscription Flood
Connection exhaustion · RPC and public API · no bound · active · first seen 2026-01-01
provenance: Reproduced in NullRabbit's attack-reproduction pipeline
mechanism
NullRabbit source-traced IOTA GraphQL unbounded-subscription flood (operator-gated).
live exposure
No exposure data. Slashr ↗ has no risk signal mapped to this technique yet — absence of data is not absence of exposure.
instances (2)
| chain | primitive | fidelity | origin | reproducer (bundle) | source |
|---|---|---|---|---|---|
| iota | iota_graphql_s1_unbounded_subs | lab | NullRabbit Labs | iota_graphql_s1_unbounded_subs | - |
| libp2p | gossipsub_subscribe_flood | lab | reverse-engineered-cve | gossipsub_subscribe_flood | GHSA-4f8r-922h-2vgv ↗ |
references
related (Connection exhaustion)
NRDAX-T0041 - Cross-Chain Peer Pool Pollution active NRDAX-T0064 - Endpoint Concurrency Cap Exhaustion active NRDAX-T0099 - Half-Open Handshake Slowloris active NRDAX-T0214 - Protocol Message Flood Unbounded Goroutine active NRDAX-T0225 - QUIC Control Frame Flood active NRDAX-T0246 - Rate-Limit Key Confusion active NRDAX-T0261 - RPC Request Flood active NRDAX-T0291 - Subscription Permit Exhaustion active
cite
https://nrdax.com/techniques/NRDAX-T0333
plain
NRDAX Registry. Technique NRDAX-T0333.
bibtex
@misc{nrdax_NRDAX_T0333,
title = {Unbounded Subscription Flood (NRDAX-T0333)},
howpublished = {NRDAX Registry},
url = {https://nrdax.com/techniques/NRDAX-T0333},
} json (csl)
{
"id": "nrdax-NRDAX-T0333",
"type": "dataset",
"title": "Unbounded Subscription Flood (NRDAX-T0333)",
"URL": "https://nrdax.com/techniques/NRDAX-T0333",
"publisher": "NRDAX Registry"
} badge
[](https://nrdax.com/techniques/NRDAX-T0333-unbounded-subscription-flood)
use from the CLI
Retrieve or cite this technique from a script or the terminal with the NRDAX Python library & CLI.
nrdax get NRDAX-T0333 nrdax cite NRDAX-T0333 --format bibtex