CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

2,071 vulnerabilities with CWE-770
CVE-2026-10600 MEDIUM
Denial of service via unbounded document content extraction in Mattermost Server
CVSS 4.3
CVE-2026-58389 HIGH
Apache Thrift: Rust binary protocol non-strict path missing string size limit
CVSS 7.5
CVE-2026-55968 HIGH
Apache Thrift: Node.js quadratic-time DoS in server receive transports
CVSS 7.5
CVE-2026-45112 HIGH
Apache Thrift: Unbounded Read Leading to Denial of Service
CVSS 7.5
CVE-2026-66037 MEDIUM
FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu()
CVSS 6.5
CVE-2026-25800 HIGH
quinn-proto has remote memory exhaustion from unbounded out-of-order stream reassembly
CVSS 7.5
CVE-2026-16756 HIGH
AWS aws-smithy-http-server < 0.66.5 - Unauthenticated Slowloris Denial of Service
CVSS 7.5
CVE-2026-8287 MEDIUM
Unrestricted File Upload in BizimHesap Information Systems' Online Pre-Accounting Software
CVSS 4.3
CVE-2026-14257 HIGH
brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash
CVSS 7.5
CVE-2026-13076 MEDIUM
MongoDB Server - Aggregation Framework Memory Exhaustion Leading to Process Termination
CVSS 6.5
CVE-2026-13075 MEDIUM
$rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggestion Generation
CVSS 6.5
CVE-2026-13074 MEDIUM
Awaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of Service
CVSS 5.3
CVE-2026-13069 MEDIUM
Queryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource Exhaustion
CVSS 6.5
CVE-2026-65650 MEDIUM
Elgg - Allocation of Resources Without Limits or Throttling
CVSS 4.3
CVE-2026-11622 HIGH
ISC BIND 9 - Potential Memory Usage Beyond Configured Limits
CVSS 7.5
CVE-2026-47013 MEDIUM
Oracle Java SE - Denial of Service
CVSS 5.3
CVE-2026-42397 MEDIUM
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
CVSS 6.5
CVE-2026-15957 HIGH
Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapes
CVSS 7.5
CVE-2026-59848 MEDIUM
Libssh: libssh: denial of service via sftp responses with unknown request ids
CVSS 5.3
CVE-2026-55831 HIGH
Netty SPDY SETTINGS frame count materializes unbounded settings map
CVSS 7.5
CVE-2026-53596 MEDIUM
FreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)
CVSS 5.3
CVE-2026-48824 MEDIUM
Mailpit < 1.30.1 - Denial of Service
CVSS 5.3
CVE-2026-45713 HIGH
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
CVSS 7.5
CVE-2026-45712 MEDIUM
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
CVSS 5.9
CVE-2026-63750 MEDIUM
SurrealDB before 3.1.0 Memory Amplification via /sql WebSocket
CVSS 5.3
Details
Vulnerabilities 2,071
Exploit Likelihood High