CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-6060 MEDIUM
OTRS 7.0.x-8.0.x, 2023.x-2025.x, <2026.3.x - Denial of Service via SQL Box Resource Consumption
CVSS 4.5
CVE-2026-5807 HIGH
Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
CVSS 7.5
CVE-2026-39313 HIGH
MCP-Framework: Unbounded memory allocation in readRequestBody allows denial of service via HTTP transport
CVE-2026-35469 MEDIUM
SpdyStream: DOS on CRI
CVSS 6.5
CVE-2026-40192 HIGH
Pillow is vulnerable to a FITS GZIP decompression bomb
CVSS 7.5
CVE-2026-3505 HIGH
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
CVSS 7.5
CVE-2026-40104 HIGH
XWiki's REST APIs can list all pages/spaces, leading to unavailability
CVSS 8.2
CVE-2026-31283 CRITICAL
Totara LMS <=v19.1.5 - Email Bombing
CVSS 9.8
CVE-2026-40395 MEDIUM
Varnish Enterprise < 6.0.16r12 - Denial of Service via Headerplus Workspace Overflow
CVSS 4.0
CVE-2026-40073 HIGH
SvelteKit <2.57.1 adapter-node - BODY_SIZE_LIMIT Bypass
CVSS 7.5
CVE-2026-35602 MEDIUM
Vikunja <2.3.0 Import Size Field - File Size Limit Bypass
CVSS 5.4
CVE-2026-39304 HIGH
Apache ActiveMQ TLSv1.3 KeyUpdate - Memory Exhaustion Denial of Service
CVSS 7.5
CVE-2026-40116 HIGH
PraisonAI's Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits
CVSS 7.5
CVE-2026-40115 MEDIUM
PraisonAI <4.5.128 WSGI Recipe Registry - Denial of Service
CVSS 6.2
CVE-2026-35633 MEDIUM
OpenClaw < 2026.3.22 - Unbounded Memory Allocation via Remote Media Error Responses
CVSS 5.3
CVE-2026-39959 HIGH
Tmds.DBus: malicious D-Bus peers can spoof signals, exhaust file descriptor resources, and cause denial of service
CVSS 7.1
CVE-2026-5440 HIGH
Memory Exhaustion via Unbounded Content-Length
CVSS 7.5
CVE-2026-5439 HIGH
Memory Exhaustion via Forged ZIP Metadata
CVSS 7.5
CVE-2026-5438 HIGH
Gzip Decompression Bomb via Content-Encoding Header
CVSS 7.5
CVE-2026-24661 LOW
Unbounded Request Body Read in MS Teams Plugin {{/changes}} Webhook Endpoint
CVSS 3.7
CVE-2026-21388 LOW
Unbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook Endpoint
CVSS 3.7
CVE-2026-40036 HIGH
Unfurl < 2026.04 - Denial of Service via Unbounded zlib Decompression
CVSS 7.5
CVE-2026-39414 MEDIUM
MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing
CVSS 6.5
CVE-2026-23869 HIGH
React Server Components 19.0.0-19.0.4 19.1.0-19.1.5 19.2.0-19.2.4 - Denial of Service via Crafted HTTP Requests
CVSS 7.5
CVE-2026-35401 HIGH
Saleor GraphQL Aliases - Resource Exhaustion
CVSS 7.5
Details
Vulnerabilities 2,071
Exploit Likelihood High