CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,720 vulnerabilities with CWE-770
CVE-2026-39804 HIGH
WebSocket permessage-deflate inflate has no output-size cap in bandit
CVE-2026-42786 HIGH
WebSocket fragmented message reassembly unbounded in bandit
CVE-2026-42788 MEDIUM
HTTP/2 frame size limit checked after body is buffered in bandit
CVE-2026-43507 MEDIUM
Prosody < 0.12.6 - Denial of Service
CVSS 5.3
CVE-2026-42198 HIGH
pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
CVSS 7.5
CVE-2026-42420 MEDIUM
OpenClaw < 2026.4.8 - Improper Base64 Decoding Size Validation
CVSS 4.3
CVE-2026-41408 MEDIUM
OpenClaw < 2026.3.31 - Disk Exhaustion via Media Download Bypass
CVSS 4.3
CVE-2026-41400 MEDIUM
OpenClaw < 2026.3.31 - Resource Consumption via Oversized WebSocket Frames in voice-call
CVSS 5.3
CVE-2026-41399 HIGH
OpenClaw < 2026.3.28 - Denial of Service via Unbounded Pre-auth WebSocket Upgrades
CVSS 7.5
CVE-2026-32688 HIGH
Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy
CVE-2026-42036 MEDIUM
Axios: HTTP adapter streamed responses bypass maxContentLength
CVSS 5.3
CVE-2026-42034 MEDIUM
Axios: HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0
CVSS 5.3
CVE-2026-41324 HIGH
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
CVSS 7.5
CVE-2026-41309 HIGH
Open Source Social Network (OSSN) Vulnerable to Resource Exhaustion via Malicious Image Processing
CVSS 8.2
CVE-2026-41173 MEDIUM
Unbounded HTTP response body read in OpenTelemetry.Sampler.AWS
CVSS 5.9
CVE-2026-41078 MEDIUM
OpenTelemetry dotnet: Potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
CVSS 5.9
CVE-2026-34062 MEDIUM
Nimiq has Allocation of Resources Without Limits or Throttling in its libp2p request/response
CVSS 5.3
CVE-2026-1660 MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2026-33595 MEDIUM
DoQ/DoH3 excessive memory allocation
CVSS 5.3
CVE-2026-33594 MEDIUM
Outgoing DoH excessive memory allocation
CVSS 5.3
CVE-2026-33254 MEDIUM
Resource exhaustion via DoQ/DoH3 connections
CVSS 5.3
CVE-2026-33260 MEDIUM
Insufficient input validation of internal webserver
CVSS 5.3
CVE-2026-33258 MEDIUM
Crafted zones can cause increased resource usage
CVSS 5.3
CVE-2026-33257 MEDIUM
Insufficient input validation of internal webserver
CVSS 5.3
CVE-2026-33256 MEDIUM
Unbounded memory allocation by internal web server
CVSS 5.3
Details
Vulnerabilities 1,720
Exploit Likelihood High