CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
2,071 vulnerabilities with CWE-770
CVE-2026-41227
HIGH
BIG-IP HTTP/2 Layer 7 Dos Protection vulnerability
CVSS 7.5
CVE-2026-40629
HIGH
F5 BIG-IP SSL/TLS - Virtual Server Denial of Service
CVSS 7.5
CVE-2026-40423
HIGH
F5 BIG-IP SIP Profile - TMM Denial of Service
CVSS 7.5
CVE-2026-39803
HIGH
HTTP/1 chunked body reader ignores length cap in bandit
CVSS 7.5
CVE-2026-44931
MEDIUM
malcontent: Disk Space Exhaustion via Globally Accessible D-Bus API
CVE-2026-8202
MEDIUM
Post-authentication CPU utilization DoS via $trim/$ltrim/$rtrim operators
CVSS 4.3
CVE-2026-40902
HIGH
PhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions
CVSS 7.5
CVE-2026-40863
HIGH
PhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader
CVSS 7.5
CVE-2026-44240
HIGH
basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
CVSS 7.5
CVE-2026-44219
LOW
ciguard: SCA HTTP client reads response body without size cap
CVSS 3.7
CVE-2026-42444
LOW
NanaZip: Unbounded resource consumption in NanaZip littlefs parser via attacker-controlled BlockCount
CVSS 3.3
CVE-2026-23826
HIGH
HPE Aruba AOS-8 Network Management Service - Unauthenticated Denial of Service
CVSS 7.5
CVE-2026-41284
HIGH
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
CVSS 7.5
CVE-2026-42006
MEDIUM
OX Dovecot Pro < 3.0.5, < 3.1.4, < 2.4.3 - Unauthenticated Uncontrolled Resource Consumption via IMAP Bracing
CVSS 4.3
CVE-2026-22925
HIGH
Siemens Simatic CN 4100 < V5.0 - Allocation of Resources Without Limits or Throttling
CVSS 7.5
CVE-2026-42256
MEDIUM
net-imap: Denial of service via high iteration count for `SCRAM-*` authentication
CVSS 6.5
CVE-2026-42294
HIGH
Argo Workflows: Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor
CVSS 7.5
CVE-2026-42189
HIGH
Russh: Pre-auth DoS via unbounded allocation in keyboard-interactive auth
CVSS 7.5
CVE-2026-44499
HIGH
ZEBRA: Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning
CVE-2026-42793
HIGH
Atom table exhaustion via attacker-controlled GraphQL SDL names in absinthe
CVSS 7.5
CVE-2026-44500
MEDIUM
ZEBRA: Allocation Amplification in Inbound Network Deserializers
CVSS 5.3
CVE-2026-43329
HIGH
netfilter: flowtable: strictly check for maximum number of actions
CVSS 7.8
CVE-2026-8124
LOW
GPAC box_code_base.c sidx_box_read allocation of resources
CVSS 3.3
CVE-2026-7541
HIGH
GitHub Enterprise Server API - Unauthenticated Denial of Service
CVSS 7.5
CVE-2026-39820
HIGH
Quadratic string concatentation in consumeComment in net/mail
CVSS 7.5
Details
Vulnerabilities
2,071
Exploit Likelihood
High