CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
2,071 vulnerabilities with CWE-770
CVE-2026-10600
MEDIUM
Denial of service via unbounded document content extraction in Mattermost Server
CVSS 4.3
CVE-2026-58389
HIGH
Apache Thrift: Rust binary protocol non-strict path missing string size limit
CVSS 7.5
CVE-2026-55968
HIGH
Apache Thrift: Node.js quadratic-time DoS in server receive transports
CVSS 7.5
CVE-2026-45112
HIGH
Apache Thrift: Unbounded Read Leading to Denial of Service
CVSS 7.5
CVE-2026-66037
MEDIUM
FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu()
CVSS 6.5
CVE-2026-25800
HIGH
quinn-proto has remote memory exhaustion from unbounded out-of-order stream reassembly
CVSS 7.5
CVE-2026-16756
HIGH
AWS aws-smithy-http-server < 0.66.5 - Unauthenticated Slowloris Denial of Service
CVSS 7.5
CVE-2026-8287
MEDIUM
Unrestricted File Upload in BizimHesap Information Systems' Online Pre-Accounting Software
CVSS 4.3
CVE-2026-14257
HIGH
brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash
CVSS 7.5
CVE-2026-13076
MEDIUM
MongoDB Server - Aggregation Framework Memory Exhaustion Leading to Process Termination
CVSS 6.5
CVE-2026-13075
MEDIUM
$rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggestion Generation
CVSS 6.5
CVE-2026-13074
MEDIUM
Awaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of Service
CVSS 5.3
CVE-2026-13069
MEDIUM
Queryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource Exhaustion
CVSS 6.5
CVE-2026-65650
MEDIUM
Elgg - Allocation of Resources Without Limits or Throttling
CVSS 4.3
CVE-2026-11622
HIGH
ISC BIND 9 - Potential Memory Usage Beyond Configured Limits
CVSS 7.5
CVE-2026-47013
MEDIUM
Oracle Java SE - Denial of Service
CVSS 5.3
CVE-2026-42397
MEDIUM
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
CVSS 6.5
CVE-2026-15957
HIGH
Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapes
CVSS 7.5
CVE-2026-59848
MEDIUM
Libssh: libssh: denial of service via sftp responses with unknown request ids
CVSS 5.3
CVE-2026-55831
HIGH
Netty SPDY SETTINGS frame count materializes unbounded settings map
CVSS 7.5
CVE-2026-53596
MEDIUM
FreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)
CVSS 5.3
CVE-2026-48824
MEDIUM
Mailpit < 1.30.1 - Denial of Service
CVSS 5.3
CVE-2026-45713
HIGH
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
CVSS 7.5
CVE-2026-45712
MEDIUM
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
CVSS 5.9
CVE-2026-63750
MEDIUM
SurrealDB before 3.1.0 Memory Amplification via /sql WebSocket
CVSS 5.3
Details
Vulnerabilities
2,071
Exploit Likelihood
High