CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-8488 MEDIUM
Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation
CVSS 4.3
CVE-2026-8486 MEDIUM
Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation
CVSS 5.3
CVE-2026-8469 HIGH
Unauthenticated denial-of-service via BEAM atom table exhaustion in phoenix_storybook
CVE-2026-3039 HIGH
BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVSS 7.5
CVE-2026-9064 HIGH
Red Hat Directory Server - LDAP Controls Denial of Service
CVSS 7.5
CVE-2026-41292 HIGH
Unbound <= 1.25.0 - Denial of Service via EDNS Option Parsing
CVSS 7.5
CVE-2026-45557 MEDIUM
Technitium DNS Server excessive DNSSEC requests
CVSS 5.8
CVE-2026-33232 HIGH
AutoGPT: Unauthenticated DoS via Disk Space Exhaustion
CVSS 7.5
CVE-2026-2325 MEDIUM
Improper Input Validation in MS Teams Meetings API Handler
CVSS 4.3
CVE-2026-44679 MEDIUM
Tuist: Forgot password flow lacks throttling for reset email delivery
CVE-2026-44216 HIGH
Wasmtime: Panic when allocating a table exceeding the size of the host's address space
CVSS 7.5
CVE-2026-8468 HIGH
Unbounded buffer accumulation in multipart header parsing causes denial of service in plug
CVE-2026-8280 MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2026-1659 HIGH
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 7.5
CVE-2026-42561 HIGH
Python-Multipart: Denial of Service via unbounded multipart part headers
CVSS 7.5
CVE-2026-28383 MEDIUM
Grafana plugin resources can lead to unbounded memory allocation
CVSS 6.5
CVE-2026-28376 MEDIUM
Grafana Live push endpoint allows unbounded memory allocation leading to OOM
CVSS 6.5
CVE-2026-8466 HIGH
Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy
CVE-2026-44248 MEDIUM
Netty: Resource exhaustion in MqttDecoder
CVSS 5.3
CVE-2026-42587 HIGH
Netty < 4.1.133.Final/4.2.13.Final HttpContentDecompressor - Decompression Bomb Denial of Service
CVSS 7.5
CVE-2026-42583 HIGH
Netty: Lz4FrameDecoder resource exhaustion
CVSS 7.5
CVE-2026-42582 HIGH
Netty: HTTP/3 QPACK literal unbounded allocation
CVSS 7.5
CVE-2026-44579 HIGH
Next.js: Denial of Service via connection exhaustion in applications using Cache Components
CVSS 7.5
CVE-2026-44004 HIGH
vm2: Host Process OOM DoS via Buffer.alloc (Timeout Bypass)
CVSS 7.5
CVE-2026-44577 MEDIUM
Next.js: Denial of Service in the Image Optimization API
CVSS 5.9
Details
Vulnerabilities 2,071
Exploit Likelihood High