CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
1,858 vulnerabilities with CWE-770
CVE-2026-29772
MEDIUM
Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands
CVSS 5.9
CVE-2026-3260
MEDIUM
Undertow: undertow: denial of service due to premature multipart/form-data parsing in get requests
CVSS 5.9
CVE-2026-33241
HIGH
Salvo < 0.89.3 - Denial of Service via Unbounded Form Data Parsing
CVSS 7.5
CVE-2026-33176
HIGH
ActiveSupport < 8.1.2.1, < 8.0.4.1, < 7.2.3.1 - Denial of Service via BigDecimal Scientific Notation Expansion
CVSS 7.5
CVE-2026-33483
HIGH
AVideo Affected by Unauthenticated Disk Space Exhaustion via Unlimited Temp File Creation in aVideoEncoderChunk.json.php
CVSS 7.5
CVE-2026-32049
HIGH
OpenClaw < 2026.2.22 - Denial of Service via Inbound Media Download Byte Limit Bypass
CVSS 7.5
CVE-2026-33155
HIGH
DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT
CVSS 7.5
CVE-2026-33012
HIGH
Micronaut Framework vulnerable to a Denial of Service in HTML error response caching
CVSS 7.5
CVE-2026-32941
MEDIUM
Sliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports
CVSS 6.5
CVE-2026-32011
HIGH
OpenClaw < 2026.3.2 - Slow-Request Denial of Service via Pre-Auth Webhook Body Parsing
CVSS 7.5
CVE-2026-28461
HIGH
OpenClaw < 2026.3.1 - Unbounded Memory Growth in Zalo Webhook via Query String Key Churn
CVSS 7.5
CVE-2026-29112
HIGH
@dicebear/converter vulnerable to ncontrolled memory allocation via crafted SVG dimensions
CVSS 7.5
CVE-2026-27979
HIGH
Next.js 16.0.1-16.1.6 - Postponed Resume Buffering Denial of Service
CVSS 7.5
CVE-2026-1376
HIGH
IBM i 7.6 - Denial of Service via Failed Authentication Connections
CVSS 7.5
CVE-2026-24458
HIGH
DoS attack via login attempts with multi-megabyte passwords
CVSS 7.5
CVE-2026-30961
MEDIUM
Gokapi < 2.2.4 - Unauthenticated Resource Exhaustion via Chunked Upload Bypass
CVSS 4.3
CVE-2026-22182
HIGH
wpDiscuz < 7.6.47 - Unauthenticated Denial of Service via Notification Email Flood
CVSS 7.5
CVE-2026-2581
MEDIUM
Undici 6.24.0-7.23.9 - Denial of Service via Deduplication Interceptor Memory Accumulation
CVSS 5.9
CVE-2026-31890
MEDIUM
inspektor-gadget < 0.50.1 - Denial of Service via Ring-Buffer Overflow
CVSS 5.5
CVE-2026-31961
MEDIUM
anchore/quill < 0.7.1 - Denial of Service via Mach-O Binary Parsing
CVSS 5.5
CVE-2026-31960
MEDIUM
anchore/quill < 0.7.1 - Denial of Service via Unbounded HTTP Response Body Read
CVSS 5.3
CVE-2026-31866
HIGH
flagd < 0.14.2 - Unauthenticated Denial of Service via Large Evaluation Context Payload
CVSS 7.5
CVE-2026-32062
HIGH
OpenClaw 2026.2.21-2-2026.2.22 & @openclaw/voice-call 2026.2.21-2026.2.22 - DoS via Media-Stream WebSocket
CVSS 7.5
CVE-2026-31826
MEDIUM
pypdf < 6.8.0 - Denial of Service via Large /Length Value in Content Stream
CVSS 5.5
CVE-2026-30946
HIGH
Parse Server <9.5.2-alpha.2/8.6.15 - DoS
CVSS 7.5
Details
Vulnerabilities
1,858
Exploit Likelihood
High