CWE-770

High likelihood

Allocation of Resources Without Limits or Throttling

Parent: CWE-400 - Uncontrolled Resource Consumption

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

1,720 vulnerabilities with CWE-770
CVE-2026-22018 LOW
Oracle Corporation Oracle Java SE < 8u481 - Denial of Service
CVSS 3.7
CVE-2026-40881 HIGH
Zebra: addr/addrv2 Deserialization Resource Exhaustion
CVSS 7.5
CVE-2026-40608 MEDIUM
Next AI Draw.io: Unbounded HTTP Body — Denial of Service
CVSS 6.2
CVE-2026-40498 CRITICAL
FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron
CVSS 9.8
CVE-2026-39396 LOW
OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVSS 3.1
CVE-2026-6060 MEDIUM
Otrs < 7.0.x - Denial of Service
CVSS 4.5
CVE-2026-5807 HIGH
Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
CVSS 7.5
CVE-2026-39313 HIGH
MCP-Framework: Unbounded memory allocation in readRequestBody allows denial of service via HTTP transport
CVE-2026-35469 HIGH
SpdyStream: DOS on CRI
CVE-2026-40192 HIGH
Pillow is vulnerable to a FITS GZIP decompression bomb
CVSS 7.5
CVE-2026-3505 HIGH
Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.
CVE-2026-40104 HIGH
XWiki's REST APIs can list all pages/spaces, leading to unavailability
CVSS 8.2
CVE-2026-31283 CRITICAL
Totara LMS <=v19.1.5 - Email Bombing
CVSS 9.8
CVE-2026-40395 MEDIUM
Varnish-software Varnish Enterprise < 6.0.16r12 - Denial of Service
CVSS 4.0
CVE-2026-40073 HIGH
SvelteKit has a BODY_SIZE_LIMIT bypass in @sveltejs/adapter-node
CVSS 7.5
CVE-2026-35602 MEDIUM
Vikunja has a File Size Limit Bypass via Vikunja Import
CVSS 5.4
CVE-2026-40116 HIGH
PraisonAI's Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits
CVSS 7.5
CVE-2026-40115 MEDIUM
PraisonAI has an Unrestricted Upload Size in WSGI Recipe Registry Server Enables Memory Exhaustion DoS
CVSS 6.2
CVE-2026-35633 MEDIUM
OpenClaw < 2026.3.22 - Unbounded Memory Allocation via Remote Media Error Responses
CVSS 5.3
CVE-2026-39959 HIGH
Tmds.DBus: malicious D-Bus peers can spoof signals, exhaust file descriptor resources, and cause denial of service
CVSS 7.1
CVE-2026-5440 HIGH
Memory Exhaustion via Unbounded Content-Length
CVSS 7.5
CVE-2026-5439 HIGH
Memory Exhaustion via Forged ZIP Metadata
CVSS 7.5
CVE-2026-5438 HIGH
Gzip Decompression Bomb via Content-Encoding Header
CVSS 7.5
CVE-2026-24661 LOW
Unbounded Request Body Read in MS Teams Plugin {{/changes}} Webhook Endpoint
CVSS 3.7
CVE-2026-21388 LOW
Unbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook Endpoint
CVSS 3.7
Details
Vulnerabilities 1,720
Exploit Likelihood High