CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-28299 HIGH
SolarWinds Web Help Desk Denial-of-Service Vulnerability
CVSS 8.2
CVE-2026-49754 HIGH
HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation
CVE-2026-48862 HIGH
Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency
CVE-2026-45682 MEDIUM
OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals
CVSS 5.1
CVE-2026-45554 MEDIUM
NiceGUI: Unauthenticated log-flood DoS via trailing slash on ESM and per-component resource routes
CVSS 5.3
CVE-2026-49140 MEDIUM
Nanobot < 0.2.1 - Authenticated Denial of Service via Matrix Media Download Handler
CVSS 4.3
CVE-2026-40990 MEDIUM
Spring Cloud Function DoS via Function Registry Overflow
CVSS 5.7
CVE-2026-10533 MEDIUM
Red Hat OpenShift - ResourceQuota Bypass Event Flood Denial of Service
CVSS 5.0
CVE-2026-49361 HIGH
Apache Fluss Netty Frame Decoder Memory Exhaustion Vulnerability
CVSS 7.5
CVE-2026-48187 MEDIUM
OTRS Email Handling - Resource Exhaustion Denial of Service
CVSS 5.7
CVE-2026-46599 HIGH
Excessive resource consumption in PackBits decompression in golang.org/x/image/tiff
CVSS 7.5
CVE-2026-45352 MEDIUM
cpp-httplib DoS: Negative chunk-size in chunked Transfer-Encoding
CVSS 5.3
CVE-2026-44697 HIGH
Klever-Go MultiDataInterceptor: remote OOM via crafted compressed P2P payload
CVSS 8.6
CVE-2026-49324 MEDIUM
Indian Scout Bobber 2025 WCM brute-force
CVSS 4.6
CVE-2026-45023 MEDIUM
AutoGP: Credit system bypassed via direct block execution in POST /api/blocks/{block_id}/execute
CVSS 5.4
CVE-2026-45292 MEDIUM
opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation
CVSS 5.3
CVE-2026-45078 MEDIUM
Synapse CPU starvation (Denial of Service)
CVSS 5.5
CVE-2026-48735 MEDIUM
pypdf: Manipulated XMP metadata streams can exhaust RAM
CVSS 5.5
CVE-2026-44247 MEDIUM
Volcano: Webhook server vulnerable to OOM due to unbounded HTTP request body size
CVSS 6.8
CVE-2026-1402 MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2026-6053 MEDIUM
IBM® Db2® is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables
CVSS 5.5
CVE-2026-1718 HIGH
IBM® Db2® is vulnerable to a denial of service with a specially crafted query when running an AUTONOMOUS procedure
CVSS 7.1
CVE-2026-47067 HIGH
Atom table exhaustion via unrecognized URL schemes in hackney
CVSS 7.5
CVE-2026-42626 MEDIUM
HP ENVY 5000 VERBASPP1N003.2237A.00 - Unauthenticated Denial of Service via Persistent TCP Connection to Port 9100
CVSS 5.9
CVE-2026-44070 LOW
Netatalk 2.0.0-4.4.2 and >=4.5.0 - Authenticated Denial of Service via Charset Conversion
CVSS 3.1
Details
Vulnerabilities 2,071
Exploit Likelihood High