CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
2,071 vulnerabilities with CWE-770
CVE-2026-41685
MEDIUM
Incus: Unbounded binary import disk exhaustion
CVSS 4.3
CVE-2026-41648
MEDIUM
Incus: Unbounded YAML Metadata Decode via Parsing
CVSS 5.0
CVE-2026-41644
HIGH
monetr is vulnerable to server-side request forgery in Lunch Flow link creation and refresh
CVSS 7.1
CVE-2026-41484
MEDIUM
OpenTelemetry.Exporter.OneCollector vulnerable to denial of service via unbounded HTTP error response body
CVSS 5.3
CVE-2026-41483
MEDIUM
Unbounded HTTP response body read in OpenTelemetry.Resources.Azure
CVSS 5.9
CVE-2026-41310
MEDIUM
OpenTelemetry .NET Zipkin exporter has unbounded remote endpoint cache leading to memory growth
CVSS 5.3
CVE-2026-6860
MEDIUM
Eclipse Vert.x 4.3.4-4.5.25, 5.0.0-5.0.10 - Improper Certificate Validation
CVSS 5.3
CVE-2026-32934
HIGH
CoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service
CVSS 7.5
CVE-2026-32689
HIGH
Long-poll NDJSON body splitting causes unbounded memory allocation in Phoenix
CVE-2026-29168
HIGH
Apache HTTP Server: mod_md unrestricted OCSP response
CVSS 7.3
CVE-2026-42437
HIGH
OpenClaw 2026.4.9 < 2026.4.10 - Denial of Service via Oversized WebSocket Frames in Voice-call Realtime Path
CVSS 7.5
CVE-2026-7776
HIGH
Boundary Workers Vulnerable to Denial of Service During TLS Handshake
CVSS 7.5
CVE-2026-7768
HIGH
@fastify/accepts-serializer vulnerable to Denial of Service via Unbounded Accept Header Cache Growth
CVSS 7.5
CVE-2026-42236
HIGH
n8n: Unauthenticated Denial of Service via MCP Client Registration
CVSS 7.5
CVE-2026-42154
HIGH
Prometheus: remote read endpoint allows denial of service via crafted snappy payload
CVSS 7.5
CVE-2026-42440
HIGH
Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader
CVSS 7.5
CVE-2026-6948
MEDIUM
Unbounded Memory Allocation in VQLResponse Result-Set Writer
CVSS 4.9
CVE-2026-42788
MEDIUM
HTTP/2 frame size limit checked after body is buffered in bandit
CVE-2026-42786
HIGH
WebSocket fragmented message reassembly unbounded in bandit
CVE-2026-39804
HIGH
WebSocket permessage-deflate inflate has no output-size cap in bandit
CVE-2026-43507
MEDIUM
Prosody < 0.12.6 and 1.0.0-13.0.0 < 13.0.5 - Unauthenticated Denial of Service via XML Parsing Resource Amplification
CVSS 5.3
CVE-2026-42198
HIGH
pgjdbc 42.2.0 to before 42.7.11 - SCRAM Authentication Denial of Service
CVSS 7.5
CVE-2026-42420
MEDIUM
OpenClaw < 2026.4.8 - Improper Base64 Decoding Size Validation
CVSS 4.3
CVE-2026-41408
MEDIUM
OpenClaw < 2026.3.31 - Disk Exhaustion via Media Download Bypass
CVSS 4.3
CVE-2026-41400
MEDIUM
OpenClaw < 2026.3.31 - Resource Consumption via Oversized WebSocket Frames in voice-call
CVSS 5.3
Details
Vulnerabilities
2,071
Exploit Likelihood
High