TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.
"https://github.com/pypa/advisory-database/blob/main/vulns/tuf/PYSEC-2020-146.yaml"