CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
1,858 vulnerabilities with CWE-770
CVE-2026-49955
MEDIUM
Hermes WebUI < 0.51.270 Resource Exhaustion via passkey/options
CVSS 5.3
CVE-2026-42570
HIGH
Svelte devalue: DoS via sparse array deserialization
CVSS 7.5
CVE-2026-41851
MEDIUM
Spring Framework Denial of Service via Unbounded Cache in SpEL
CVSS 5.3
CVE-2026-41710
MEDIUM
Cache Exhaustion in Stateful Retries leads to Denial of Service
CVSS 5.9
CVE-2026-41007
HIGH
Spring HATEOAS heap exhaustion through unbounded internal caching
CVSS 7.5
CVE-2026-43973
HIGH
gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion
CVE-2026-45290
HIGH
Cloudburst Network has DoS in RakNet connection handling due to missing bound checks
CVSS 7.5
CVE-2026-50589
MEDIUM
Openstack Ironic < 35.0.1 - Allocation of Resources Without Limits or Throttling
CVSS 5.3
CVE-2026-40898
MEDIUM
quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
CVSS 5.3
CVE-2026-36499
MEDIUM
Open vSwitch v3.6.90 - Denial of Service via Excessive Thread Allocation in udpif_set_threads()
CVSS 6.5
CVE-2026-44545
MEDIUM
Unbounded WebSocket message and frame sizes can cause unauthenticated remote denial of service
CVSS 5.3
CVE-2026-48597
HIGH
Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint
CVE-2026-35202
LOW
Pterodactyl Panel <1.12.3 Client API - Database Limit Bypass
CVE-2026-34077
HIGH
React Router vulnerable to Denial of Service via reflected user input in single-fetch
CVSS 7.5
CVE-2026-28299
HIGH
SolarWinds Web Help Desk Denial-of-Service Vulnerability
CVSS 8.2
CVE-2026-49754
HIGH
HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation
CVE-2026-48862
HIGH
Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency
CVE-2026-45682
MEDIUM
OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals
CVSS 5.1
CVE-2026-45554
MEDIUM
NiceGUI: Unauthenticated log-flood DoS via trailing slash on ESM and per-component resource routes
CVSS 5.3
CVE-2026-49140
MEDIUM
Nanobot < 0.2.1 - Authenticated Denial of Service via Matrix Media Download Handler
CVSS 4.3
CVE-2026-40990
MEDIUM
Spring Cloud Function DoS via Function Registry Overflow
CVSS 5.7
CVE-2026-10533
MEDIUM
Red Hat OpenShift - ResourceQuota Bypass Event Flood Denial of Service
CVSS 5.0
CVE-2026-49361
HIGH
Apache Fluss Netty Frame Decoder Memory Exhaustion Vulnerability
CVSS 7.5
CVE-2026-48187
MEDIUM
OTRS Email Handling - Resource Exhaustion Denial of Service
CVSS 5.7
CVE-2026-46599
HIGH
Excessive resource consumption in PackBits decompression in golang.org/x/image/tiff
CVSS 7.5
Details
Vulnerabilities
1,858
Exploit Likelihood
High