CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-41399 HIGH
OpenClaw < 2026.3.28 - Denial of Service via Unbounded Pre-auth WebSocket Upgrades
CVSS 7.5
CVE-2026-32688 HIGH
Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy
CVSS 7.5
CVE-2026-42039 HIGH
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
CVSS 7.5
CVE-2026-42036 MEDIUM
Axios: HTTP adapter streamed responses bypass maxContentLength
CVSS 5.3
CVE-2026-42034 MEDIUM
Axios: HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0
CVSS 5.3
CVE-2026-21728 HIGH
Tempo query limit results in unbounded memory allocation
CVSS 7.5
CVE-2026-41324 HIGH
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
CVSS 7.5
CVE-2026-41309 HIGH
Open Source Social Network (OSSN) Vulnerable to Resource Exhaustion via Malicious Image Processing
CVSS 8.2
CVE-2026-41173 MEDIUM
Unbounded HTTP response body read in OpenTelemetry.Sampler.AWS
CVSS 5.9
CVE-2026-41078 MEDIUM
OpenTelemetry dotnet: Potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
CVSS 5.9
CVE-2026-34062 MEDIUM
Nimiq has Allocation of Resources Without Limits or Throttling in its libp2p request/response
CVSS 5.3
CVE-2026-1660 MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2026-33595 MEDIUM
DoQ/DoH3 excessive memory allocation
CVSS 5.3
CVE-2026-33594 MEDIUM
Outgoing DoH excessive memory allocation
CVSS 5.3
CVE-2026-33254 MEDIUM
Resource exhaustion via DoQ/DoH3 connections
CVSS 5.3
CVE-2026-33260 MEDIUM
Insufficient input validation of internal webserver
CVSS 5.3
CVE-2026-33258 MEDIUM
Crafted zones can cause increased resource usage
CVSS 5.3
CVE-2026-33257 MEDIUM
Insufficient input validation of internal webserver
CVSS 5.3
CVE-2026-33256 MEDIUM
Unbounded memory allocation by internal web server
CVSS 5.3
CVE-2026-22018 LOW
Oracle Java SE & GraalVM DoS via Libraries (8u481, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26)
CVSS 3.7
CVE-2026-40881 HIGH
Zebra: addr/addrv2 Deserialization Resource Exhaustion
CVSS 7.5
CVE-2026-33812 MEDIUM
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image
CVSS 6.1
CVE-2026-40608 MEDIUM
Next AI Draw.io: Unbounded HTTP Body — Denial of Service
CVSS 6.2
CVE-2026-40498 CRITICAL
FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron
CVSS 9.8
CVE-2026-39396 LOW
OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVSS 3.1
Details
Vulnerabilities 2,071
Exploit Likelihood High