CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
2,071 vulnerabilities with CWE-770
CVE-2026-55497
MEDIUM
Cloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS)
CVSS 6.5
CVE-2026-14539
MEDIUM
Denial of Service via Unrestricted Payload Buffering in MCP Toolbox
CVE-2026-12733
HIGH
IBM DataPower Gateway affected by denial of service
CVSS 7.5
CVE-2026-16308
HIGH
IBM Enterprise Build of Quarkus is affected by a DoS vulnerability
CVSS 7.5
CVE-2026-11897
HIGH
IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability with HTTP/2
CVSS 7.5
CVE-2026-18362
MEDIUM
DFIR-IRIS Missing Brute Force Protection in User Authentication
CVSS 5.9
CVE-2026-16971
MEDIUM
DFIR-IRIS Missing Brute Force Protection in OTP Validation
CVSS 5.9
CVE-2026-67437
HIGH
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
CVSS 7.5
CVE-2026-67432
HIGH
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
CVSS 7.5
CVE-2026-67430
MEDIUM
MCP Ruby SDK < 0.23.0 - StreamableHTTPTransport Memory Exhaustion
CVSS 5.3
CVE-2026-63119
MEDIUM
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
CVSS 6.2
CVE-2026-15975
HIGH
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 7.5
CVE-2026-59899
MEDIUM
Netty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service
CVE-2026-15144
HIGH
@fastify/rate-limit vulnerable to rate-limit bypass via IPv6 address rotation
CVSS 7.3
CVE-2026-54638
HIGH
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
CVSS 7.5
CVE-2026-54609
HIGH
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
CVSS 8.6
CVE-2026-54345
MEDIUM
gopacket < 1.6.1 - Diameter AVP Integer Underflow Denial of Service
CVE-2026-54332
MEDIUM
Gopacket < 1.6.1 - Denial of Service
CVE-2026-61609
HIGH
Pterodactyl Panel >= 1.7.0, < 1.13.0 - Auth Rate-Limit Denial of Service
CVSS 7.5
CVE-2026-47483
HIGH
Nvidia Dcgm - Allocation of Resources Without Limits or Throttling
CVSS 8.2
CVE-2026-65624
MEDIUM
Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion
CVE-2026-59248
HIGH
Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS
CVE-2026-64646
MEDIUM
Next.js: Unbounded Server Action payload in Edge runtime
CVSS 5.3
CVE-2026-59251
HIGH
Denial of service via exponential certificate policy tree growth in path validation
CVE-2026-42792
MEDIUM
epmd permanent DoS via EMFILE on accept(2) in erts
Details
Vulnerabilities
2,071
Exploit Likelihood
High