CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-32062 HIGH
OpenClaw 2026.2.21-2-2026.2.22 & @openclaw/voice-call 2026.2.21-2026.2.22 - DoS via Media-Stream WebSocket
CVSS 7.5
CVE-2026-31826 MEDIUM
pypdf < 6.8.0 - Denial of Service via Large /Length Value in Content Stream
CVSS 5.5
CVE-2026-30946 HIGH
Parse Server <9.5.2-alpha.2/8.6.15 - DoS
CVSS 7.5
CVE-2026-26130 HIGH
Microsoft.AspNetCore.App.Runtime 8.0.0-8.0.24 - Unauthenticated Denial of Service
CVSS 7.5
CVE-2026-30827 HIGH
express-rate-limit 8.0.0-8.0.1 - DoS
CVSS 7.5
CVE-2026-29795 MEDIUM
stellar-xdr <25.0.1 - Memory Corruption
CVSS 4.0
CVE-2026-26018 HIGH
CoreDNS < 1.14.2 - Denial of Service via Predictable PRNG in Loop Detection Plugin
CVSS 7.5
CVE-2026-29062 HIGH
jackson-core 3.0.0-3.1.0 - Denial of Service via UTF8DataInputJsonParser and ReaderBasedJsonParser
CVSS 7.5
CVE-2026-29612 MEDIUM
OpenClaw < 2026.2.14 - Denial of Service via Large Base64 Media File Decoding
CVSS 5.5
CVE-2026-29609 HIGH
OpenClaw < 2026.2.14 - Denial of Service via Unbounded URL-Backed Media Fetch
CVSS 7.5
CVE-2026-28478 HIGH
OpenClaw < 2026.2.13 - Unauthenticated Denial of Service via Webhook Request Body Buffering
CVSS 7.5
CVE-2026-28452 MEDIUM
OpenClaw < 2026.2.14 - Denial of Service via Unguarded Archive Extraction
CVSS 5.5
CVE-2026-28394 MEDIUM
OpenClaw < 2026.2.15 - Denial of Service via Unbounded Response Parsing in Web Fetch Tool
CVSS 6.5
CVE-2026-28342 HIGH
olivetin < 3000.10.2 - Unauthenticated Denial of Service via PasswordHash Endpoint
CVSS 7.5
CVE-2026-26998 MEDIUM
Traefik <2.11.38/3.6.9 - Memory Corruption
CVSS 4.4
CVE-2026-20103 HIGH
Cisco ASA & FTD Unauthenticated DoS via Remote Access SSL VPN
CVSS 8.6
CVE-2026-3520 HIGH
Multer < 2.1.1 - Denial of Service via Malformed Request
CVSS 7.5
CVE-2026-27932 HIGH
joserfc < 1.6.3 - Unauthenticated Denial of Service via PBES2 Count Parameter
CVSS 7.5
CVE-2026-27601 MEDIUM
Underscore.js < 1.13.8 - Denial of Service via Recursive Data Structure in _.flatten and _.isEqual
CVSS 5.9
CVE-2026-25673 HIGH
Django 6.0-6.0.2/5.2-5.2.11/4.2-4.2.28 - DoS
CVSS 7.5
CVE-2026-27887 MEDIUM
Spin < 3.6.1, SpinKube < 0.6.2, containerd-shim-spin < 0.22.1 - Denial of Service via Unbounded Response Buffering
CVE-2026-27633 HIGH
TinyWeb < 2.02 - Unauthenticated Denial of Service via Large Content-Length Header
CVSS 7.5
CVE-2026-27630 HIGH
TinyWeb < 2.02 - Unauthenticated Denial of Service via Slowloris Attack
CVSS 7.5
CVE-2026-2845 MEDIUM
GitLab 11.2-18.7.4, 18.8-18.8.4, 18.9-18.9.0 - Authenticated Denial of Service via Bitbucket Server Import Endpoint
CVSS 6.5
CVE-2026-1725 MEDIUM
GitLab 18.9 - Unauthenticated Denial of Service via CI Jobs API Endpoint
CVSS 5.3
Details
Vulnerabilities 2,071
Exploit Likelihood High