CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
1,858 vulnerabilities with CWE-770
CVE-2026-0531
MEDIUM
Kibana 7.10.0-7.17.29 - Authenticated Denial of Service via Bulk Retrieval Request
CVSS 6.5
CVE-2026-0530
MEDIUM
Kibana 7.10.0-7.17.29 - Denial of Service via Fleet Resource Exhaustion
CVSS 6.5
CVE-2026-22773
MEDIUM
vLLM 0.6.4-0.11.9 - Denial of Service via Malformed 1x1 Pixel Image
CVSS 6.5
CVE-2026-22025
LOW
CryptoLib < 1.4.3 - Use-After-Free in KMC Server Error Handling
CVSS 3.7
CVE-2025-46638
HIGH
Dell Bsafe Ssl-j < 7.4 - Allocation of Resources Without Limits or Throttling
CVSS 7.5
CVE-2025-11482
HIGH
Allocation of Resources Without Limits or Throttling in the OPC-UA Server
CVSS 7.5
CVE-2025-57798
MEDIUM
Joplin has Denial of Service (DoS) via Uncontrolled Resource Allocation through Title Input
CVSS 5.5
CVE-2025-14870
HIGH
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 7.5
CVE-2025-32425
MEDIUM
AutoGPT < 0.6.32 Platform Containers - Docker Log Disk Exhaustion Denial of Service
CVSS 5.5
CVE-2025-69233
MEDIUM
Apache CloudStack: Domain/account resources limits not honored
CVSS 6.5
CVE-2025-14341
HIGH
Input Data Manipulation in DivvyDrive Information Technologies' DivvyDrive
CVSS 8.3
CVE-2025-66369
HIGH
Samsung Exynos MM - Denial of Service via 5G NR NAS Registration Accept Message Handling
CVSS 7.5
CVE-2025-70071
MEDIUM
Assimp 6.0.2 - Denial of Service via FBX Parser Vector Data Array
CVSS 5.9
CVE-2025-70069
HIGH
Assimp 6.0.2 - Denial of Service via FBXConverter.cpp ConvertMeshMultiMaterial Method
CVSS 7.5
CVE-2025-36122
MEDIUM
IBM® Db2® is vulnerable to a denial of service with a specially crafted query when stmtheap is set to automatic
CVSS 6.5
CVE-2025-51846
HIGH
CryptPad unbounded WebSocket frame flood
CVSS 7.5
CVE-2025-6016
MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2025-3922
MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2025-0186
MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2025-66487
LOW
IBM Aspera Shares 1.9.9-1.11.0 - Email Rate Limit Denial of Service
CVSS 2.7
CVE-2025-13436
MEDIUM
Allocation of Resources Without Limits or Throttling in GitLab
CVSS 6.5
CVE-2025-13929
HIGH
GitLab 10.0-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Unauthenticated Denial of Service via Repository Archive Endpoint
CVSS 7.5
CVE-2025-13690
MEDIUM
GitLab 16.11-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Authenticated Denial of Service via Webhook Custom Header Input
CVSS 6.5
CVE-2025-12576
MEDIUM
GitLab 9.3-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Authenticated Denial of Service via Webhook Response Handling
CVSS 6.5
CVE-2025-3525
MEDIUM
GitLab 9.0-18.7.4, 18.8-18.8.4, 18.9-18.9.0 - Authenticated Denial of Service via CI Trigger API
CVSS 6.5
Details
Vulnerabilities
1,858
Exploit Likelihood
High