CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-41227 HIGH
BIG-IP HTTP/2 Layer 7 Dos Protection vulnerability
CVSS 7.5
CVE-2026-40629 HIGH
F5 BIG-IP SSL/TLS - Virtual Server Denial of Service
CVSS 7.5
CVE-2026-40423 HIGH
F5 BIG-IP SIP Profile - TMM Denial of Service
CVSS 7.5
CVE-2026-39803 HIGH
HTTP/1 chunked body reader ignores length cap in bandit
CVSS 7.5
CVE-2026-44931 MEDIUM
malcontent: Disk Space Exhaustion via Globally Accessible D-Bus API
CVE-2026-8202 MEDIUM
Post-authentication CPU utilization DoS via $trim/$ltrim/$rtrim operators
CVSS 4.3
CVE-2026-40902 HIGH
PhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions
CVSS 7.5
CVE-2026-40863 HIGH
PhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader
CVSS 7.5
CVE-2026-44240 HIGH
basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
CVSS 7.5
CVE-2026-44219 LOW
ciguard: SCA HTTP client reads response body without size cap
CVSS 3.7
CVE-2026-42444 LOW
NanaZip: Unbounded resource consumption in NanaZip littlefs parser via attacker-controlled BlockCount
CVSS 3.3
CVE-2026-23826 HIGH
HPE Aruba AOS-8 Network Management Service - Unauthenticated Denial of Service
CVSS 7.5
CVE-2026-41284 HIGH
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
CVSS 7.5
CVE-2026-42006 MEDIUM
OX Dovecot Pro < 3.0.5, < 3.1.4, < 2.4.3 - Unauthenticated Uncontrolled Resource Consumption via IMAP Bracing
CVSS 4.3
CVE-2026-22925 HIGH
Siemens Simatic CN 4100 < V5.0 - Allocation of Resources Without Limits or Throttling
CVSS 7.5
CVE-2026-42256 MEDIUM
net-imap: Denial of service via high iteration count for `SCRAM-*` authentication
CVSS 6.5
CVE-2026-42294 HIGH
Argo Workflows: Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor
CVSS 7.5
CVE-2026-42189 HIGH
Russh: Pre-auth DoS via unbounded allocation in keyboard-interactive auth
CVSS 7.5
CVE-2026-44499 HIGH
ZEBRA: Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning
CVE-2026-42793 HIGH
Atom table exhaustion via attacker-controlled GraphQL SDL names in absinthe
CVSS 7.5
CVE-2026-44500 MEDIUM
ZEBRA: Allocation Amplification in Inbound Network Deserializers
CVSS 5.3
CVE-2026-43329 HIGH
netfilter: flowtable: strictly check for maximum number of actions
CVSS 7.8
CVE-2026-8124 LOW
GPAC box_code_base.c sidx_box_read allocation of resources
CVSS 3.3
CVE-2026-7541 HIGH
GitHub Enterprise Server API - Unauthenticated Denial of Service
CVSS 7.5
CVE-2026-39820 HIGH
Quadratic string concatentation in consumeComment in net/mail
CVSS 7.5
Details
Vulnerabilities 2,071
Exploit Likelihood High