CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
2,071 vulnerabilities with CWE-770
CVE-2026-28299
HIGH
SolarWinds Web Help Desk Denial-of-Service Vulnerability
CVSS 8.2
CVE-2026-49754
HIGH
HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation
CVE-2026-48862
HIGH
Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency
CVE-2026-45682
MEDIUM
OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals
CVSS 5.1
CVE-2026-45554
MEDIUM
NiceGUI: Unauthenticated log-flood DoS via trailing slash on ESM and per-component resource routes
CVSS 5.3
CVE-2026-49140
MEDIUM
Nanobot < 0.2.1 - Authenticated Denial of Service via Matrix Media Download Handler
CVSS 4.3
CVE-2026-40990
MEDIUM
Spring Cloud Function DoS via Function Registry Overflow
CVSS 5.7
CVE-2026-10533
MEDIUM
Red Hat OpenShift - ResourceQuota Bypass Event Flood Denial of Service
CVSS 5.0
CVE-2026-49361
HIGH
Apache Fluss Netty Frame Decoder Memory Exhaustion Vulnerability
CVSS 7.5
CVE-2026-48187
MEDIUM
OTRS Email Handling - Resource Exhaustion Denial of Service
CVSS 5.7
CVE-2026-46599
HIGH
Excessive resource consumption in PackBits decompression in golang.org/x/image/tiff
CVSS 7.5
CVE-2026-45352
MEDIUM
cpp-httplib DoS: Negative chunk-size in chunked Transfer-Encoding
CVSS 5.3
CVE-2026-44697
HIGH
Klever-Go MultiDataInterceptor: remote OOM via crafted compressed P2P payload
CVSS 8.6
CVE-2026-49324
MEDIUM
Indian Scout Bobber 2025 WCM brute-force
CVSS 4.6
CVE-2026-45023
MEDIUM
AutoGP: Credit system bypassed via direct block execution in POST /api/blocks/{block_id}/execute
CVSS 5.4
CVE-2026-45292
MEDIUM
opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation
CVSS 5.3
CVE-2026-45078
MEDIUM
Synapse CPU starvation (Denial of Service)
CVSS 5.5
CVE-2026-48735
MEDIUM
pypdf: Manipulated XMP metadata streams can exhaust RAM
CVSS 5.5
CVE-2026-44247
MEDIUM
Volcano: Webhook server vulnerable to OOM due to unbounded HTTP request body size
CVSS 6.8
CVE-2026-1402
MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2026-6053
MEDIUM
IBM® Db2® is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables
CVSS 5.5
CVE-2026-1718
HIGH
IBM® Db2® is vulnerable to a denial of service with a specially crafted query when running an AUTONOMOUS procedure
CVSS 7.1
CVE-2026-47067
HIGH
Atom table exhaustion via unrecognized URL schemes in hackney
CVSS 7.5
CVE-2026-42626
MEDIUM
HP ENVY 5000 VERBASPP1N003.2237A.00 - Unauthenticated Denial of Service via Persistent TCP Connection to Port 9100
CVSS 5.9
CVE-2026-44070
LOW
Netatalk 2.0.0-4.4.2 and >=4.5.0 - Authenticated Denial of Service via Charset Conversion
CVSS 3.1
Details
Vulnerabilities
2,071
Exploit Likelihood
High