CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-41685 MEDIUM
Incus: Unbounded binary import disk exhaustion
CVSS 4.3
CVE-2026-41648 MEDIUM
Incus: Unbounded YAML Metadata Decode via Parsing
CVSS 5.0
CVE-2026-41644 HIGH
monetr is vulnerable to server-side request forgery in Lunch Flow link creation and refresh
CVSS 7.1
CVE-2026-41484 MEDIUM
OpenTelemetry.Exporter.OneCollector vulnerable to denial of service via unbounded HTTP error response body
CVSS 5.3
CVE-2026-41483 MEDIUM
Unbounded HTTP response body read in OpenTelemetry.Resources.Azure
CVSS 5.9
CVE-2026-41310 MEDIUM
OpenTelemetry .NET Zipkin exporter has unbounded remote endpoint cache leading to memory growth
CVSS 5.3
CVE-2026-6860 MEDIUM
Eclipse Vert.x 4.3.4-4.5.25, 5.0.0-5.0.10 - Improper Certificate Validation
CVSS 5.3
CVE-2026-32934 HIGH
CoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service
CVSS 7.5
CVE-2026-32689 HIGH
Long-poll NDJSON body splitting causes unbounded memory allocation in Phoenix
CVE-2026-29168 HIGH
Apache HTTP Server: mod_md unrestricted OCSP response
CVSS 7.3
CVE-2026-42437 HIGH
OpenClaw 2026.4.9 < 2026.4.10 - Denial of Service via Oversized WebSocket Frames in Voice-call Realtime Path
CVSS 7.5
CVE-2026-7776 HIGH
Boundary Workers Vulnerable to Denial of Service During TLS Handshake
CVSS 7.5
CVE-2026-7768 HIGH
@fastify/accepts-serializer vulnerable to Denial of Service via Unbounded Accept Header Cache Growth
CVSS 7.5
CVE-2026-42236 HIGH
n8n: Unauthenticated Denial of Service via MCP Client Registration
CVSS 7.5
CVE-2026-42154 HIGH
Prometheus: remote read endpoint allows denial of service via crafted snappy payload
CVSS 7.5
CVE-2026-42440 HIGH
Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader
CVSS 7.5
CVE-2026-6948 MEDIUM
Unbounded Memory Allocation in VQLResponse Result-Set Writer
CVSS 4.9
CVE-2026-42788 MEDIUM
HTTP/2 frame size limit checked after body is buffered in bandit
CVE-2026-42786 HIGH
WebSocket fragmented message reassembly unbounded in bandit
CVE-2026-39804 HIGH
WebSocket permessage-deflate inflate has no output-size cap in bandit
CVE-2026-43507 MEDIUM
Prosody < 0.12.6 and 1.0.0-13.0.0 < 13.0.5 - Unauthenticated Denial of Service via XML Parsing Resource Amplification
CVSS 5.3
CVE-2026-42198 HIGH
pgjdbc 42.2.0 to before 42.7.11 - SCRAM Authentication Denial of Service
CVSS 7.5
CVE-2026-42420 MEDIUM
OpenClaw < 2026.4.8 - Improper Base64 Decoding Size Validation
CVSS 4.3
CVE-2026-41408 MEDIUM
OpenClaw < 2026.3.31 - Disk Exhaustion via Media Download Bypass
CVSS 4.3
CVE-2026-41400 MEDIUM
OpenClaw < 2026.3.31 - Resource Consumption via Oversized WebSocket Frames in voice-call
CVSS 5.3
Details
Vulnerabilities 2,071
Exploit Likelihood High