CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
1,720 vulnerabilities with CWE-770
CVE-2026-22018
LOW
Oracle Corporation Oracle Java SE < 8u481 - Denial of Service
CVSS 3.7
CVE-2026-40881
HIGH
Zebra: addr/addrv2 Deserialization Resource Exhaustion
CVSS 7.5
CVE-2026-40608
MEDIUM
Next AI Draw.io: Unbounded HTTP Body — Denial of Service
CVSS 6.2
CVE-2026-40498
CRITICAL
FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron
CVSS 9.8
CVE-2026-39396
LOW
OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVSS 3.1
CVE-2026-6060
MEDIUM
Otrs < 7.0.x - Denial of Service
CVSS 4.5
CVE-2026-5807
HIGH
Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
CVSS 7.5
CVE-2026-39313
HIGH
MCP-Framework: Unbounded memory allocation in readRequestBody allows denial of service via HTTP transport
CVE-2026-35469
HIGH
SpdyStream: DOS on CRI
CVE-2026-40192
HIGH
Pillow is vulnerable to a FITS GZIP decompression bomb
CVSS 7.5
CVE-2026-3505
HIGH
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
CVE-2026-40104
HIGH
XWiki's REST APIs can list all pages/spaces, leading to unavailability
CVSS 8.2
CVE-2026-31283
CRITICAL
Totara LMS <=v19.1.5 - Email Bombing
CVSS 9.8
CVE-2026-40395
MEDIUM
Varnish-software Varnish Enterprise < 6.0.16r12 - Denial of Service
CVSS 4.0
CVE-2026-40073
HIGH
SvelteKit has a BODY_SIZE_LIMIT bypass in @sveltejs/adapter-node
CVSS 7.5
CVE-2026-35602
MEDIUM
Vikunja has a File Size Limit Bypass via Vikunja Import
CVSS 5.4
CVE-2026-40116
HIGH
PraisonAI's Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits
CVSS 7.5
CVE-2026-40115
MEDIUM
PraisonAI has an Unrestricted Upload Size in WSGI Recipe Registry Server Enables Memory Exhaustion DoS
CVSS 6.2
CVE-2026-35633
MEDIUM
OpenClaw < 2026.3.22 - Unbounded Memory Allocation via Remote Media Error Responses
CVSS 5.3
CVE-2026-39959
HIGH
Tmds.DBus: malicious D-Bus peers can spoof signals, exhaust file descriptor resources, and cause denial of service
CVSS 7.1
CVE-2026-5440
HIGH
Memory Exhaustion via Unbounded Content-Length
CVSS 7.5
CVE-2026-5439
HIGH
Memory Exhaustion via Forged ZIP Metadata
CVSS 7.5
CVE-2026-5438
HIGH
Gzip Decompression Bomb via Content-Encoding Header
CVSS 7.5
CVE-2026-24661
LOW
Unbounded Request Body Read in MS Teams Plugin {{/changes}} Webhook Endpoint
CVSS 3.7
CVE-2026-21388
LOW
Unbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook Endpoint
CVSS 3.7
Details
Vulnerabilities
1,720
Exploit Likelihood
High