CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
1,720 vulnerabilities with CWE-770
CVE-2026-39804
HIGH
WebSocket permessage-deflate inflate has no output-size cap in bandit
CVE-2026-42786
HIGH
WebSocket fragmented message reassembly unbounded in bandit
CVE-2026-42788
MEDIUM
HTTP/2 frame size limit checked after body is buffered in bandit
CVE-2026-43507
MEDIUM
Prosody < 0.12.6 - Denial of Service
CVSS 5.3
CVE-2026-42198
HIGH
pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
CVSS 7.5
CVE-2026-42420
MEDIUM
OpenClaw < 2026.4.8 - Improper Base64 Decoding Size Validation
CVSS 4.3
CVE-2026-41408
MEDIUM
OpenClaw < 2026.3.31 - Disk Exhaustion via Media Download Bypass
CVSS 4.3
CVE-2026-41400
MEDIUM
OpenClaw < 2026.3.31 - Resource Consumption via Oversized WebSocket Frames in voice-call
CVSS 5.3
CVE-2026-41399
HIGH
OpenClaw < 2026.3.28 - Denial of Service via Unbounded Pre-auth WebSocket Upgrades
CVSS 7.5
CVE-2026-32688
HIGH
Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy
CVE-2026-42036
MEDIUM
Axios: HTTP adapter streamed responses bypass maxContentLength
CVSS 5.3
CVE-2026-42034
MEDIUM
Axios: HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0
CVSS 5.3
CVE-2026-41324
HIGH
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
CVSS 7.5
CVE-2026-41309
HIGH
Open Source Social Network (OSSN) Vulnerable to Resource Exhaustion via Malicious Image Processing
CVSS 8.2
CVE-2026-41173
MEDIUM
Unbounded HTTP response body read in OpenTelemetry.Sampler.AWS
CVSS 5.9
CVE-2026-41078
MEDIUM
OpenTelemetry dotnet: Potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
CVSS 5.9
CVE-2026-34062
MEDIUM
Nimiq has Allocation of Resources Without Limits or Throttling in its libp2p request/response
CVSS 5.3
CVE-2026-1660
MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2026-33595
MEDIUM
DoQ/DoH3 excessive memory allocation
CVSS 5.3
CVE-2026-33594
MEDIUM
Outgoing DoH excessive memory allocation
CVSS 5.3
CVE-2026-33254
MEDIUM
Resource exhaustion via DoQ/DoH3 connections
CVSS 5.3
CVE-2026-33260
MEDIUM
Insufficient input validation of internal webserver
CVSS 5.3
CVE-2026-33258
MEDIUM
Crafted zones can cause increased resource usage
CVSS 5.3
CVE-2026-33257
MEDIUM
Insufficient input validation of internal webserver
CVSS 5.3
CVE-2026-33256
MEDIUM
Unbounded memory allocation by internal web server
CVSS 5.3
Details
Vulnerabilities
1,720
Exploit Likelihood
High