CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
2,071 vulnerabilities with CWE-770
CVE-2026-41399
HIGH
OpenClaw < 2026.3.28 - Denial of Service via Unbounded Pre-auth WebSocket Upgrades
CVSS 7.5
CVE-2026-32688
HIGH
Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy
CVSS 7.5
CVE-2026-42039
HIGH
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
CVSS 7.5
CVE-2026-42036
MEDIUM
Axios: HTTP adapter streamed responses bypass maxContentLength
CVSS 5.3
CVE-2026-42034
MEDIUM
Axios: HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0
CVSS 5.3
CVE-2026-21728
HIGH
Tempo query limit results in unbounded memory allocation
CVSS 7.5
CVE-2026-41324
HIGH
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
CVSS 7.5
CVE-2026-41309
HIGH
Open Source Social Network (OSSN) Vulnerable to Resource Exhaustion via Malicious Image Processing
CVSS 8.2
CVE-2026-41173
MEDIUM
Unbounded HTTP response body read in OpenTelemetry.Sampler.AWS
CVSS 5.9
CVE-2026-41078
MEDIUM
OpenTelemetry dotnet: Potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
CVSS 5.9
CVE-2026-34062
MEDIUM
Nimiq has Allocation of Resources Without Limits or Throttling in its libp2p request/response
CVSS 5.3
CVE-2026-1660
MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2026-33595
MEDIUM
DoQ/DoH3 excessive memory allocation
CVSS 5.3
CVE-2026-33594
MEDIUM
Outgoing DoH excessive memory allocation
CVSS 5.3
CVE-2026-33254
MEDIUM
Resource exhaustion via DoQ/DoH3 connections
CVSS 5.3
CVE-2026-33260
MEDIUM
Insufficient input validation of internal webserver
CVSS 5.3
CVE-2026-33258
MEDIUM
Crafted zones can cause increased resource usage
CVSS 5.3
CVE-2026-33257
MEDIUM
Insufficient input validation of internal webserver
CVSS 5.3
CVE-2026-33256
MEDIUM
Unbounded memory allocation by internal web server
CVSS 5.3
CVE-2026-22018
LOW
Oracle Java SE & GraalVM DoS via Libraries (8u481, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26)
CVSS 3.7
CVE-2026-40881
HIGH
Zebra: addr/addrv2 Deserialization Resource Exhaustion
CVSS 7.5
CVE-2026-33812
MEDIUM
Excessive memory allocation when decoding malicious SFNT in golang.org/x/image
CVSS 6.1
CVE-2026-40608
MEDIUM
Next AI Draw.io: Unbounded HTTP Body — Denial of Service
CVSS 6.2
CVE-2026-40498
CRITICAL
FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron
CVSS 9.8
CVE-2026-39396
LOW
OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVSS 3.1
Details
Vulnerabilities
2,071
Exploit Likelihood
High